CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-4960
6.4 MEDIUM

The WCFM Marketplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wcfm_stores' shortcode in versions up to, and including, 3.6.2 due to insufficient …

Jan 11, 2024
CVE-2023-4372
6.4 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'esi' shortcode in versions up to, and including, 5.6 due to …

Jan 11, 2024
CVE-2023-4248
5.4 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2023-4247
5.4 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2023-4246
4.3 MEDIUM

The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.33.3. This is due to missing or incorrect …

Jan 11, 2024
CVE-2023-37644
5.5 MEDIUM

SWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf. This occurs in png_read_chunk in lib/png.c.

Jan 11, 2024
CVE-2023-6883
4.3 MEDIUM

The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in …

Jan 11, 2024
CVE-2023-6520
4.3 MEDIUM

The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. …

Jan 11, 2024
CVE-2023-6506
4.3 MEDIUM

The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jan 11, 2024
CVE-2023-6446
4.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due …

Jan 11, 2024
CVE-2023-6223
4.3 MEDIUM

The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API …

Jan 11, 2024
CVE-2023-6630
4.3 MEDIUM

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jan 11, 2024
CVE-2024-22195
5.4 MEDIUM

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML …

Jan 11, 2024
CVE-2023-52274
6.1 MEDIUM

member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.

Jan 11, 2024
CVE-2023-45171
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of …

Jan 11, 2024
CVE-2023-45169
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a …

Jan 11, 2024
CVE-2023-38267
6.2 MEDIUM

IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user …

Jan 11, 2024
CVE-2023-31001
5.1 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in …

Jan 11, 2024
CVE-2022-40361
6.1 MEDIUM

Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.

Jan 11, 2024
CVE-2023-45175
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a …

Jan 11, 2024
CVE-2023-45173
6.2 MEDIUM

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a …

Jan 11, 2024
CVE-2024-21667
6.5 MEDIUM

pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature …

Jan 11, 2024
CVE-2024-21666
6.5 MEDIUM

The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access …

Jan 11, 2024
CVE-2024-21665
4.3 MEDIUM

ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the …

Jan 11, 2024
CVE-2024-0333
5.3 MEDIUM

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via …

Jan 10, 2024
CVE-2023-49295
6.4 MEDIUM

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out …

Jan 10, 2024
CVE-2023-42941
4.8 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.2 and iPadOS 17.2. An attacker in a privileged network position may …

Jan 10, 2024
CVE-2023-42934
4.2 MEDIUM

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An …

Jan 10, 2024
CVE-2023-42929
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.

Jan 10, 2024
CVE-2023-42872
5.5 MEDIUM

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be …

Jan 10, 2024
CVE-2023-42865
6.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS …

Jan 10, 2024
CVE-2023-42862
6.5 MEDIUM

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, tvOS 16.4, iOS 16.4 and iPadOS 16.4, watchOS …

Jan 10, 2024
CVE-2023-42831
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey …

Jan 10, 2024
CVE-2023-42829
5.5 MEDIUM

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, …

Jan 10, 2024
CVE-2023-41994
5.5 MEDIUM

A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the …

Jan 10, 2024
CVE-2023-41987
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access sensitive user data.

Jan 10, 2024
CVE-2023-41069
5.5 MEDIUM

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to …

Jan 10, 2024
CVE-2023-40438
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14, iOS 16.7 and iPadOS 16.7. An app …

Jan 10, 2024
CVE-2023-40437
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura …

Jan 10, 2024
CVE-2023-40433
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.

Jan 10, 2024
CVE-2023-40430
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes …

Jan 10, 2024
CVE-2023-40411
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.

Jan 10, 2024
CVE-2023-40385
6.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A …

Jan 10, 2024
CVE-2023-38607
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sonoma 14. An app may be able to modify Printer …

Jan 10, 2024
CVE-2023-32424
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.4 and iPadOS 16.4, watchOS 9.4. An attacker that has already …

Jan 10, 2024
CVE-2023-28185
5.5 MEDIUM

An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, …

Jan 10, 2024
CVE-2022-48577
5.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-48504
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-46710
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be …

Jan 10, 2024
CVE-2022-42816
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.