CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20932
7.5 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are …

Jan 16, 2024
CVE-2024-20930
6.3 MEDIUM

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK). …

Jan 16, 2024
CVE-2024-20928
6.1 MEDIUM

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20926
5.9 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are …

Jan 16, 2024
CVE-2024-20924
7.6 HIGH

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker …

Jan 16, 2024
CVE-2024-20922
2.5 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java …

Jan 16, 2024
CVE-2024-20920
3.8 LOW

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged …

Jan 16, 2024
CVE-2024-20918
7.4 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Jan 16, 2024
CVE-2024-20916
8.3 HIGH

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily …

Jan 16, 2024
CVE-2024-20914
2.3 LOW

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20912
2.7 LOW

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with …

Jan 16, 2024
CVE-2024-20910
3.0 LOW

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker …

Jan 16, 2024
CVE-2024-20908
6.1 MEDIUM

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20906
4.8 MEDIUM

Vulnerability in the Integrated Lights Out Manager (ILOM) product of Oracle Systems (component: System Management). Supported versions that are affected are 3, 4 and 5. …

Jan 16, 2024
CVE-2024-20904
5.0 MEDIUM

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily …

Jan 16, 2024
CVE-2024-0603
7.3 HIGH

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of …

Jan 16, 2024
CVE-2024-0601
6.3 MEDIUM

A vulnerability was found in ZhongFuCheng3y Austin 1.0. It has been rated as critical. Affected by this issue is the function getRemoteUrl2File of the file …

Jan 16, 2024
CVE-2024-0519
8.8 HIGH KEV

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jan 16, 2024
CVE-2024-0518
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Jan 16, 2024
CVE-2024-0517
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Jan 16, 2024
CVE-2023-52068
6.1 MEDIUM

kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.

Jan 16, 2024
CVE-2023-52042
9.8 CRITICAL

An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.

Jan 16, 2024
CVE-2023-39691
9.8 CRITICAL

An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.

Jan 16, 2024
CVE-2023-36236
4.8 MEDIUM

Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

Jan 16, 2024
CVE-2023-21901
7.4 HIGH

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, …

Jan 16, 2024
CVE-2022-31021
3.3 LOW

Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds …

Jan 16, 2024
CVE-2023-48926
5.3 MEDIUM

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

Jan 16, 2024
CVE-2024-0599
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java …

Jan 16, 2024
CVE-2023-6336
7.2 HIGH

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2023-6335
6.4 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2023-6334
5.3 MEDIUM

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: …

Jan 16, 2024
CVE-2023-5097
7.0 HIGH

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2024-22491
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the post/save content parameter.

Jan 16, 2024
CVE-2024-0507
6.5 MEDIUM

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management …

Jan 16, 2024
CVE-2024-0200
7.2 HIGH

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled …

Jan 16, 2024
CVE-2023-7234
5.3 MEDIUM

OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.

Jan 16, 2024
CVE-2023-52041
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.

Jan 16, 2024
CVE-2023-51381

Rejected reason: This CVE ID has been rejected or withdrawn by GitHub.

Jan 16, 2024
CVE-2023-49351
9.8 CRITICAL

A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack …

Jan 16, 2024
CVE-2024-23347
7.8 HIGH

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that …

Jan 16, 2024
CVE-2024-22628
7.2 HIGH

Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=

Jan 16, 2024
CVE-2024-22627
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.

Jan 16, 2024
CVE-2024-22626
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=.

Jan 16, 2024
CVE-2024-22625
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.

Jan 16, 2024
CVE-2023-37523
5.6 MEDIUM

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2023-22525

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

Jan 16, 2024
CVE-2023-22520

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

Jan 16, 2024
CVE-2023-22514
7.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code …

Jan 16, 2024
CVE-2023-22512
7.5 HIGH

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, …

Jan 16, 2024
CVE-2023-22510

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.