CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-32931
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to …

Jan 10, 2024
CVE-2022-32919
4.7 MEDIUM

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that …

Jan 10, 2024
CVE-2023-29447
5.7 MEDIUM

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Jan 10, 2024
CVE-2023-29446
4.7 MEDIUM

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows …

Jan 10, 2024
CVE-2022-45793
5.5 MEDIUM

Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution …

Jan 10, 2024
CVE-2023-48783
5.4 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and …

Jan 10, 2024
CVE-2023-37934
4.3 MEDIUM

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service …

Jan 10, 2024
CVE-2023-37932
6.5 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker …

Jan 10, 2024
CVE-2023-29444
6.3 MEDIUM

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they …

Jan 10, 2024
CVE-2023-50172
5.3 MEDIUM

A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-49864
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49863
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49862
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49715
4.3 MEDIUM

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-47171
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-6158
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a …

Jan 10, 2024
CVE-2024-0389
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The …

Jan 10, 2024
CVE-2024-20715
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20714
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20713
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20712
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20711
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20710
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2023-5455
6.5 MEDIUM

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting …

Jan 10, 2024
CVE-2023-48261
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48260
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48259
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48258
5.5 MEDIUM

The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

Jan 10, 2024
CVE-2023-48256
5.3 MEDIUM

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL …

Jan 10, 2024
CVE-2023-48255
6.3 MEDIUM

The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session …

Jan 10, 2024
CVE-2023-48254
5.3 MEDIUM

The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

Jan 10, 2024
CVE-2024-0310
6.1 MEDIUM

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to …

Jan 10, 2024
CVE-2023-48249
6.5 MEDIUM

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user …

Jan 10, 2024
CVE-2023-48248
5.5 MEDIUM

The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution …

Jan 10, 2024
CVE-2023-48247
5.3 MEDIUM

The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48246
6.5 MEDIUM

The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) …

Jan 10, 2024
CVE-2023-48245
6.5 MEDIUM

The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48244
5.3 MEDIUM

The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

Jan 10, 2024
CVE-2023-48242
6.5 MEDIUM

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user …

Jan 10, 2024
CVE-2023-51252
5.4 MEDIUM

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files …

Jan 10, 2024
CVE-2023-50120
5.5 MEDIUM

MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial …

Jan 10, 2024
CVE-2023-49394
6.1 MEDIUM

Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

Jan 10, 2024
CVE-2020-26630
4.9 MEDIUM

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload …

Jan 10, 2024
CVE-2020-26628
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via …

Jan 10, 2024
CVE-2020-26627
4.9 MEDIUM

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload …

Jan 10, 2024
CVE-2023-41603
5.3 MEDIUM

D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the …

Jan 10, 2024
CVE-2023-41781
5.7 MEDIUM

There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

Jan 10, 2024
CVE-2024-0364
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The …

Jan 10, 2024
CVE-2024-0363
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 10, 2024
CVE-2024-0362
5.5 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.