CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23868
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23867
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23866
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23865
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23864
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23863
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23862
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23861
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23860
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23859
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23858
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23857
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23856
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-0920
7.2 HIGH

A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admin_ping.htm of the …

Jan 26, 2024
CVE-2024-0919
8.8 HIGH

A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. …

Jan 26, 2024
CVE-2024-0918
7.2 HIGH

A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request …

Jan 26, 2024
CVE-2024-0727
5.5 MEDIUM

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading …

Jan 26, 2024
CVE-2022-48622
7.8 HIGH

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in …

Jan 26, 2024
CVE-2024-22545
7.8 HIGH

An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The …

Jan 26, 2024
CVE-2023-6919
7.5 HIGH

Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal.This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.

Jan 26, 2024
CVE-2023-48129
5.4 MEDIUM

An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2024-23388
6.1 MEDIUM

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a …

Jan 26, 2024
CVE-2023-48135
5.4 MEDIUM

An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48133
5.4 MEDIUM

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48132
5.4 MEDIUM

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48131
5.4 MEDIUM

An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48130
5.4 MEDIUM

An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48128
5.4 MEDIUM

An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48127
5.4 MEDIUM

An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48126
5.4 MEDIUM

An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-38323
9.8 CRITICAL

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have …

Jan 26, 2024
CVE-2023-38319
9.8 CRITICAL

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the FAS key entry in the configuration file, allowing attackers that have direct …

Jan 26, 2024
CVE-2023-38318
9.8 CRITICAL

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers that have direct …

Jan 26, 2024
CVE-2023-38317
9.8 CRITICAL

An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing attackers that have …

Jan 26, 2024
CVE-2023-6159
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5612
5.3 MEDIUM

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to …

Jan 26, 2024
CVE-2024-21387
5.3 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21385
8.3 HIGH

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 26, 2024
CVE-2024-21383
3.3 LOW

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21382
4.3 MEDIUM

Microsoft Edge for Android Information Disclosure Vulnerability

Jan 26, 2024
CVE-2024-21326
9.6 CRITICAL

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 26, 2024
CVE-2024-0456
4.3 MEDIUM

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able …

Jan 26, 2024
CVE-2024-0402
9.9 CRITICAL

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5933
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper …

Jan 26, 2024
CVE-2024-23630
9.0 CRITICAL

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is …

Jan 26, 2024
CVE-2024-23629
9.6 CRITICAL

An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve …

Jan 26, 2024
CVE-2024-23628
9.0 CRITICAL

A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23627
9.0 CRITICAL

A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23626
9.0 CRITICAL

A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication …

Jan 26, 2024
CVE-2024-23625
9.6 CRITICAL

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution …

Jan 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.