CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-38626
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38625
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-38624
5.4 MEDIUM

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal …

Jan 23, 2024
CVE-2023-7238
7.1 HIGH

A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the …

Jan 23, 2024
CVE-2023-6926
8.4 HIGH

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate …

Jan 23, 2024
CVE-2023-46889
5.7 MEDIUM

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In …

Jan 23, 2024
CVE-2023-42144
5.5 MEDIUM

Cleartext Transmission during initial setup in Shelly TRV 20220811-15234 v.2.1.8 allows a local attacker to obtain the Wi-Fi password.

Jan 23, 2024
CVE-2023-42143
5.4 MEDIUM

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the …

Jan 23, 2024
CVE-2024-22497
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Jan 23, 2024
CVE-2023-51210
9.8 CRITICAL

SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

Jan 23, 2024
CVE-2024-23636
9.8 CRITICAL

SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a …

Jan 23, 2024
CVE-2024-23341
6.1 MEDIUM

TuiTse-TsuSin is a package for organizing the comparative corpus of Taiwanese Chinese characters and Roman characters, and extracting sentences of the Taiwanese Chinese characters and …

Jan 23, 2024
CVE-2024-23330
5.3 MEDIUM

Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from …

Jan 23, 2024
CVE-2024-22417
6.1 MEDIUM

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22205
9.1 CRITICAL

Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and …

Jan 23, 2024
CVE-2024-22204
5.3 MEDIUM

Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in Whoogle are enabled. …

Jan 23, 2024
CVE-2024-22203
9.1 CRITICAL

Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2023-6573
5.5 MEDIUM

HPE OneView may have a missing passphrase during restore.

Jan 23, 2024
CVE-2023-45889
6.1 MEDIUM

A Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject JavaScript into any webpage. NOTE: this issue …

Jan 23, 2024
CVE-2024-22496
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.

Jan 23, 2024
CVE-2024-22490
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the /index keyword parameter.

Jan 23, 2024
CVE-2023-50275
7.5 HIGH

HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

Jan 23, 2024
CVE-2023-50274
7.8 HIGH

HPE OneView may allow command injection with local privilege escalation.

Jan 23, 2024
CVE-2024-23854

Rejected reason: This CVE ID was unused by the CNA.

Jan 23, 2024
CVE-2024-22663
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg

Jan 23, 2024
CVE-2024-22662
9.8 CRITICAL

TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules

Jan 23, 2024
CVE-2024-22660
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg

Jan 23, 2024
CVE-2023-49657
9.6 CRITICAL

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a …

Jan 23, 2024
CVE-2024-0755
8.8 HIGH

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume …

Jan 23, 2024
CVE-2024-0754
6.5 MEDIUM

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Jan 23, 2024
CVE-2024-0753
6.5 MEDIUM

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird …

Jan 23, 2024
CVE-2024-0752
6.5 MEDIUM

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in …

Jan 23, 2024
CVE-2024-0751
8.8 HIGH

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Jan 23, 2024
CVE-2024-0750
8.8 HIGH

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects …

Jan 23, 2024
CVE-2024-0749
4.3 MEDIUM

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0748
4.3 MEDIUM

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar …

Jan 23, 2024
CVE-2024-0747
6.5 MEDIUM

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. …

Jan 23, 2024
CVE-2024-0746
6.5 MEDIUM

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, …

Jan 23, 2024
CVE-2024-0745
8.8 HIGH

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < …

Jan 23, 2024
CVE-2024-0744
7.5 HIGH

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0743
7.5 HIGH

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, …

Jan 23, 2024
CVE-2024-0742
4.3 MEDIUM

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to …

Jan 23, 2024
CVE-2024-0741
6.5 MEDIUM

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2023-49783
4.3 MEDIUM

Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch …

Jan 23, 2024
CVE-2023-48714
4.3 MEDIUM

Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should …

Jan 23, 2024
CVE-2023-44401
5.3 MEDIUM

The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks …

Jan 23, 2024
CVE-2024-22705
7.8 HIGH

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between …

Jan 23, 2024
CVE-2024-22076
9.8 CRITICAL

MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.

Jan 23, 2024
CVE-2024-0703
4.4 MEDIUM

The Sticky Buttons – floating buttons builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sticky URLs in all versions up to, and …

Jan 23, 2024
CVE-2023-51043
7.0 HIGH

In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.