CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52367
7.7 HIGH

Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.

Feb 18, 2024
CVE-2023-52366
7.5 HIGH

Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52387
7.5 HIGH

Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52365
5.3 MEDIUM

Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52363
5.3 MEDIUM

Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by …

Feb 18, 2024
CVE-2023-52362
7.5 HIGH

Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52361
7.5 HIGH

The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.

Feb 18, 2024
CVE-2023-52360
7.5 HIGH

Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.

Feb 18, 2024
CVE-2023-52358
6.2 MEDIUM

Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52357
7.5 HIGH

Vulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52097
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2024-25113

Rejected reason: This CVE was misassigned. See CVE-2023-47623 for the canonical reference.

Feb 17, 2024
CVE-2022-42443
2.2 LOW

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow …

Feb 17, 2024
CVE-2022-41738
7.5 HIGH

IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: …

Feb 17, 2024
CVE-2022-41737
7.1 HIGH

IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate connections from a container outside the current namespace. …

Feb 17, 2024
CVE-2024-22337
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2024-22336
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2024-22335
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2023-50951
4.0 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid …

Feb 17, 2024
CVE-2024-1512
9.8 CRITICAL

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter …

Feb 17, 2024
CVE-2024-0610
9.8 CRITICAL

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, …

Feb 17, 2024
CVE-2024-25468
7.5 HIGH

An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.

Feb 17, 2024
CVE-2024-25298
7.2 HIGH

An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.

Feb 17, 2024
CVE-2024-25297
4.8 MEDIUM

Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

Feb 17, 2024
CVE-2024-21500
4.8 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the …

Feb 17, 2024
CVE-2024-21499
4.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability …

Feb 17, 2024
CVE-2024-21498
5.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with …

Feb 17, 2024
CVE-2024-21497
5.4 MEDIUM

Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into …

Feb 17, 2024
CVE-2024-21496
6.1 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header …

Feb 17, 2024
CVE-2024-21495
6.5 MEDIUM

Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be …

Feb 17, 2024
CVE-2024-21494
5.4 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can …

Feb 17, 2024
CVE-2024-21493
5.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library …

Feb 17, 2024
CVE-2024-21492
4.8 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User …

Feb 17, 2024
CVE-2024-22727
8.3 HIGH

Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB.

Feb 17, 2024
CVE-2023-31728
7.0 HIGH

Teltonika RUT240 devices with firmware before 07.04.2, when bridge mode is used, sometimes make SSH and HTTP services available on the IPv6 WAN interface even …

Feb 17, 2024
CVE-2024-20986
6.1 MEDIUM

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20984
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and …

Feb 17, 2024
CVE-2024-20982
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20980
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20978
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20976
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20974
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20972
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20970
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20968
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Difficult to …

Feb 17, 2024
CVE-2024-20966
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20964
5.3 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and …

Feb 17, 2024
CVE-2024-20962
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20960
6.5 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: RAPID). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20958
5.4 MEDIUM

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Feb 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.