CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-43993
5.4 MEDIUM

An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43992
5.4 MEDIUM

An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43991
5.4 MEDIUM

An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43990
5.4 MEDIUM

An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43989
5.4 MEDIUM

An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43988
5.4 MEDIUM

An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2024-0665
6.1 MEDIUM

The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 …

Jan 24, 2024
CVE-2024-22372
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Jan 24, 2024
CVE-2024-22366
6.8 MEDIUM

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the …

Jan 24, 2024
CVE-2024-22380
5.5 MEDIUM

Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier …

Jan 24, 2024
CVE-2024-21796
5.5 MEDIUM

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict …

Jan 24, 2024
CVE-2024-21765
5.5 MEDIUM

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and …

Jan 24, 2024
CVE-2022-4964
5.5 MEDIUM

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

Jan 24, 2024
CVE-2024-23638
6.5 MEDIUM

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial …

Jan 24, 2024
CVE-2024-23633
4.7 MEDIUM

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was …

Jan 24, 2024
CVE-2024-23453
5.5 MEDIUM

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application …

Jan 24, 2024
CVE-2024-0814
6.5 MEDIUM

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. …

Jan 24, 2024
CVE-2024-0811
4.3 MEDIUM

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0810
4.3 MEDIUM

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak …

Jan 24, 2024
CVE-2024-0809
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security …

Jan 24, 2024
CVE-2024-0805
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security …

Jan 24, 2024
CVE-2023-35836
6.5 MEDIUM

An issue was discovered in SolaX Pocket WiFi 3 through 3.001.02. An attacker within RF range can obtain a cleartext copy of the network configuration …

Jan 23, 2024
CVE-2023-7237
5.7 MEDIUM

Lantronix XPort sends weakly encoded credentials within web request headers.

Jan 23, 2024
CVE-2023-52330
6.1 MEDIUM

A cross-site scripting vulnerability in Trend Micro Apex Central could allow a remote attacker to execute arbitrary code on affected installations of Trend Micro Apex …

Jan 23, 2024
CVE-2023-52329
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52328
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52327
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-52326
6.1 MEDIUM

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code …

Jan 23, 2024
CVE-2023-41178
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41177
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-41176
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerabilities in Trend Micro Mobile Security (Enterprise) could allow an exploit against an authenticated victim that visits a malicious link provided …

Jan 23, 2024
CVE-2023-38627
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38626
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38625
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38624
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-46889
5.7 MEDIUM

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In …

Jan 23, 2024
CVE-2023-42144
5.5 MEDIUM

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Jan 23, 2024
CVE-2023-42143
5.4 MEDIUM

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the …

Jan 23, 2024
CVE-2024-22497
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Jan 23, 2024
CVE-2024-23341
6.1 MEDIUM

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and …

Jan 23, 2024
CVE-2024-23330
5.3 MEDIUM

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from …

Jan 23, 2024
CVE-2024-22417
6.1 MEDIUM

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22204
5.3 MEDIUM

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. …

Jan 23, 2024
CVE-2023-6573
5.5 MEDIUM

HPE OneView may have a missing passphrase during restore.

Jan 23, 2024
CVE-2023-45889
6.1 MEDIUM

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue …

Jan 23, 2024
CVE-2024-22496
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.

Jan 23, 2024
CVE-2024-22490
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

Jan 23, 2024
CVE-2024-0754
6.5 MEDIUM

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Jan 23, 2024
CVE-2024-0753
6.5 MEDIUM

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird …

Jan 23, 2024
CVE-2024-0752
6.5 MEDIUM

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in …

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.