CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52322
6.1 MEDIUM

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

Jan 4, 2024
CVE-2023-29962
6.5 MEDIUM

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

Jan 4, 2024
CVE-2023-6738
5.4 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' …

Jan 4, 2024
CVE-2023-6733
6.5 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. …

Jan 4, 2024
CVE-2023-6498
4.4 MEDIUM

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Jan 4, 2024
CVE-2024-20809
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20808
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20806
6.2 MEDIUM

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

Jan 4, 2024
CVE-2024-20804
4.0 MEDIUM

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20803
6.8 MEDIUM

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

Jan 4, 2024
CVE-2024-20802
4.6 MEDIUM

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

Jan 4, 2024
CVE-2023-5138
6.8 MEDIUM

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

Jan 3, 2024
CVE-2023-6540
6.5 MEDIUM

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload …

Jan 3, 2024
CVE-2023-5879
6.8 MEDIUM

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on …

Jan 3, 2024
CVE-2024-21631
6.5 MEDIUM

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may …

Jan 3, 2024
CVE-2024-21622
5.4 MEDIUM

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 …

Jan 3, 2024
CVE-2023-6004
4.8 MEDIUM

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may …

Jan 3, 2024
CVE-2023-46742
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the …

Jan 3, 2024
CVE-2023-46741
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive …

Jan 3, 2024
CVE-2023-46740
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used …

Jan 3, 2024
CVE-2023-46739
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could …

Jan 3, 2024
CVE-2024-21911
6.1 MEDIUM

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21910
6.1 MEDIUM

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would …

Jan 3, 2024
CVE-2024-21908
6.1 MEDIUM

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2023-46738
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated …

Jan 3, 2024
CVE-2023-30617
6.5 MEDIUM

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has …

Jan 3, 2024
CVE-2023-50093
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

Jan 3, 2024
CVE-2023-50092
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).

Jan 3, 2024
CVE-2024-0201
5.4 MEDIUM

The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function …

Jan 3, 2024
CVE-2023-7068
4.3 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Jan 3, 2024
CVE-2023-6984
5.3 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Jan 3, 2024
CVE-2023-6747
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, …

Jan 3, 2024
CVE-2023-6621
6.1 MEDIUM

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a …

Jan 3, 2024
CVE-2023-52313
4.7 MEDIUM

FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52312
4.7 MEDIUM

Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52308
4.7 MEDIUM

FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52306
4.7 MEDIUM

FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52305
4.7 MEDIUM

FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52303
4.7 MEDIUM

Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52302
4.7 MEDIUM

Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38678
4.7 MEDIUM

OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38677
4.7 MEDIUM

FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38676
4.7 MEDIUM

Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38675
4.7 MEDIUM

FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38674
4.7 MEDIUM

FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-6986
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Jan 3, 2024
CVE-2023-6981
6.1 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter …

Jan 3, 2024
CVE-2023-6980
4.3 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Jan 3, 2024
CVE-2023-6524
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and …

Jan 3, 2024
CVE-2023-6629
6.1 MEDIUM

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.