CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21633
7.8 HIGH

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource …

Jan 3, 2024
CVE-2024-21909
7.5 HIGH

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted …

Jan 3, 2024
CVE-2024-21907
7.5 HIGH

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a …

Jan 3, 2024
CVE-2023-45559
8.2 HIGH

An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 3, 2024
CVE-2023-37607
7.5 HIGH

Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the …

Jan 3, 2024
CVE-2023-37608
7.5 HIGH

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin …

Jan 3, 2024
CVE-2023-51785
7.5 HIGH

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack …

Jan 3, 2024
CVE-2023-52309
8.2 HIGH

Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

Jan 3, 2024
CVE-2023-52307
8.2 HIGH

Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2023-52304
8.2 HIGH

Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2024-0211
7.8 HIGH

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0210
7.8 HIGH

Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0209
7.8 HIGH

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0208
7.8 HIGH

GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0207
7.8 HIGH

HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2023-50922
7.2 HIGH

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a …

Jan 3, 2024
CVE-2023-47473
7.5 HIGH

Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.

Jan 3, 2024
CVE-2023-6600
8.6 HIGH

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to …

Jan 3, 2024
CVE-2023-42358
7.7 HIGH

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a …

Jan 3, 2024
CVE-2023-7027
7.2 HIGH

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 3, 2024
CVE-2023-50343
8.3 HIGH

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow …

Jan 3, 2024
CVE-2023-50342
7.1 HIGH

HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result …

Jan 3, 2024
CVE-2023-50341
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" …

Jan 3, 2024
CVE-2023-45724
8.2 HIGH

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

Jan 3, 2024
CVE-2023-45723
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file …

Jan 3, 2024
CVE-2023-45722
8.8 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to …

Jan 3, 2024
CVE-2023-50351
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity …

Jan 3, 2024
CVE-2023-50350
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

Jan 3, 2024
CVE-2023-49553
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.

Jan 2, 2024
CVE-2023-49552
7.5 HIGH

An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the …

Jan 2, 2024
CVE-2023-49551
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.

Jan 2, 2024
CVE-2023-49550
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

Jan 2, 2024
CVE-2023-49549
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.

Jan 2, 2024
CVE-2024-21632
8.6 HIGH

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute …

Jan 2, 2024
CVE-2023-50020
7.5 HIGH

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Jan 2, 2024
CVE-2023-4164
8.4 HIGH

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional …

Jan 2, 2024
CVE-2024-21627
8.1 HIGH

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using …

Jan 2, 2024
CVE-2023-45893
7.5 HIGH

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive …

Jan 2, 2024
CVE-2023-45892
7.5 HIGH

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

Jan 2, 2024
CVE-2022-3010
7.5 HIGH

The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate …

Jan 2, 2024
CVE-2024-0193
7.8 HIGH

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, …

Jan 2, 2024
CVE-2023-47039
7.8 HIGH

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell …

Jan 2, 2024
CVE-2023-43514
8.4 HIGH

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Jan 2, 2024
CVE-2023-43512
7.5 HIGH

Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual …

Jan 2, 2024
CVE-2023-43511
7.5 HIGH

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

Jan 2, 2024
CVE-2023-33120
7.8 HIGH

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

Jan 2, 2024
CVE-2023-33118
7.8 HIGH

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

Jan 2, 2024
CVE-2023-33117
7.8 HIGH

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

Jan 2, 2024
CVE-2023-33116
7.5 HIGH

Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

Jan 2, 2024
CVE-2023-33114
8.4 HIGH

Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.