CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0232
4.7 MEDIUM

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim …

Jan 16, 2024
CVE-2024-0569
4.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting …

Jan 16, 2024
CVE-2024-0553
7.5 HIGH

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 …

Jan 16, 2024
CVE-2024-0556
7.1 HIGH

A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and …

Jan 16, 2024
CVE-2024-0555
4.6 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could lead another user into executing unwanted actions …

Jan 16, 2024
CVE-2024-0554
5.5 MEDIUM

A Cross-site scripting (XSS) vulnerability has been found on WIC1200, affecting version 1.1. An authenticated user could store a malicious javascript payload in the device …

Jan 16, 2024
CVE-2023-52106
4.4 MEDIUM

Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jan 16, 2024
CVE-2023-52105
7.5 HIGH

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52104
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52103
9.8 CRITICAL

Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.

Jan 16, 2024
CVE-2023-52102
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52101
9.1 CRITICAL

Component exposure vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service availability and integrity.

Jan 16, 2024
CVE-2023-52100
7.5 HIGH

The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52099
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-34063
9.9 CRITICAL

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

Jan 16, 2024
CVE-2023-52116
7.5 HIGH

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 16, 2024
CVE-2023-52115
7.5 HIGH

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

Jan 16, 2024
CVE-2023-52114
7.5 HIGH

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52108
7.5 HIGH

Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52107
7.5 HIGH

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52098
7.5 HIGH

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52113
7.5 HIGH

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52112
5.3 MEDIUM

Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 16, 2024
CVE-2023-52111
7.5 HIGH

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52110
7.5 HIGH

The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52109
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-4566
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44117
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44112
7.5 HIGH

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

Jan 16, 2024
CVE-2011-10005
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in EasyFTP 1.7.0.2. Affected is an unknown function of the component MKD Command Handler. The manipulation …

Jan 16, 2024
CVE-2024-21674
7.5 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21673
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21672
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2023-22527
9.8 CRITICAL KEV

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers …

Jan 16, 2024
CVE-2023-22526
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a …

Jan 16, 2024
CVE-2024-22428
7.0 HIGH

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and …

Jan 16, 2024
CVE-2024-22362
7.5 HIGH

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) …

Jan 16, 2024
CVE-2023-51282
7.5 HIGH

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

Jan 16, 2024
CVE-2023-51257
7.8 HIGH

An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.

Jan 16, 2024
CVE-2023-51059
8.8 HIGH

An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component …

Jan 16, 2024
CVE-2023-43449
8.8 HIGH

An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

Jan 16, 2024
CVE-2023-6457
6.6 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue …

Jan 16, 2024
CVE-2023-51810
7.5 HIGH

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the …

Jan 16, 2024
CVE-2023-49107
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before …

Jan 16, 2024
CVE-2023-49106
4.6 MEDIUM

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

Jan 16, 2024
CVE-2023-48104
6.1 MEDIUM

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

Jan 16, 2024
CVE-2023-47460
8.8 HIGH

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

Jan 16, 2024
CVE-2023-47459
6.5 MEDIUM

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

Jan 16, 2024
CVE-2023-41619
6.1 MEDIUM

Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.

Jan 16, 2024
CVE-2023-7206
7.8 HIGH

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, …

Jan 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.