CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50344
5.4 MEDIUM

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

Jan 3, 2024
CVE-2023-41783
4.3 MEDIUM

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit …

Jan 3, 2024
CVE-2023-41780
6.4 MEDIUM

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could …

Jan 3, 2024
CVE-2023-41779
4.4 MEDIUM

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the …

Jan 3, 2024
CVE-2023-41776
6.7 MEDIUM

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

Jan 3, 2024
CVE-2023-49558
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49557
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

Jan 3, 2024
CVE-2023-49556
5.5 MEDIUM

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

Jan 3, 2024
CVE-2023-49555
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49554
5.5 MEDIUM

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2024-21629
5.9 MEDIUM

Rust EVM is an Ethereum Virtual Machine interpreter. In `rust-evm`, a feature called `record_external_operation` was introduced, allowing library users to record custom gas changes. This …

Jan 2, 2024
CVE-2024-21628
5.4 MEDIUM

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to …

Jan 2, 2024
CVE-2024-0196
6.3 MEDIUM

A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 2, 2024
CVE-2023-50019
5.9 MEDIUM

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration …

Jan 2, 2024
CVE-2024-0195
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to …

Jan 2, 2024
CVE-2024-0194
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of …

Jan 2, 2024
CVE-2023-45561
5.3 MEDIUM

An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 2, 2024
CVE-2024-0192
6.3 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jan 2, 2024
CVE-2024-0191
5.3 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the …

Jan 2, 2024
CVE-2023-51652
6.1 MEDIUM

OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0, there is a potential for a …

Jan 2, 2024
CVE-2023-50711
5.7 MEDIUM

vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starting in version 0.5.0 and prior to version 0.12.0, …

Jan 2, 2024
CVE-2023-49794
6.7 MEDIUM

KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in KernelSU kernel module can …

Jan 2, 2024
CVE-2023-7192
5.5 MEDIUM

A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to …

Jan 2, 2024
CVE-2023-6693
4.9 MEDIUM

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest …

Jan 2, 2024
CVE-2023-48732
4.3 MEDIUM

Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was …

Jan 2, 2024
CVE-2023-47858
4.3 MEDIUM

Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived …

Jan 2, 2024
CVE-2023-49142
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.

Jan 2, 2024
CVE-2023-49135
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-48360
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.

Jan 2, 2024
CVE-2023-47857
4.0 MEDIUM

in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.

Jan 2, 2024
CVE-2023-33038
6.7 MEDIUM

Memory corruption while receiving a message in Bus Socket Transport Server.

Jan 2, 2024
CVE-2023-28583
6.7 MEDIUM

Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.

Jan 2, 2024
CVE-2023-26157
5.5 MEDIUM

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

Jan 2, 2024
CVE-2023-32891
6.7 MEDIUM

In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32885
6.7 MEDIUM

In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System …

Jan 2, 2024
CVE-2023-32884
6.7 MEDIUM

In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System execution …

Jan 2, 2024
CVE-2023-32883
6.7 MEDIUM

In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Jan 2, 2024
CVE-2023-32882
6.7 MEDIUM

In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution …

Jan 2, 2024
CVE-2023-32881
4.4 MEDIUM

In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. …

Jan 2, 2024
CVE-2023-32880
4.4 MEDIUM

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32879
6.7 MEDIUM

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32878
4.4 MEDIUM

In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32877
6.7 MEDIUM

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32876
4.4 MEDIUM

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32875
4.4 MEDIUM

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32872
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32831
5.5 MEDIUM

In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no …

Jan 2, 2024
CVE-2024-0185
4.7 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affects some unknown processing of …

Jan 2, 2024
CVE-2023-6485
5.4 MEDIUM

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around …

Jan 1, 2024
CVE-2023-6037
4.8 MEDIUM

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.