CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6683
6.5 MEDIUM

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and …

Jan 12, 2024
CVE-2023-31035
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at …

Jan 12, 2024
CVE-2023-31034
6.6 MEDIUM

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A …

Jan 12, 2024
CVE-2023-31033
6.8 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . …

Jan 12, 2024
CVE-2023-31032
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability …

Jan 12, 2024
CVE-2023-31031
4.2 MEDIUM

NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A …

Jan 12, 2024
CVE-2023-31030
9.3 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially …

Jan 12, 2024
CVE-2023-31029
9.3 CRITICAL

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by …

Jan 12, 2024
CVE-2023-31025
6.5 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to …

Jan 12, 2024
CVE-2023-31024
9.0 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially …

Jan 12, 2024
CVE-2024-0463
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 12, 2024
CVE-2024-0462
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2024-21887
9.1 CRITICAL KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send …

Jan 12, 2024
CVE-2024-0461
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php …

Jan 12, 2024
CVE-2023-46805
8.2 HIGH KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources …

Jan 12, 2024
CVE-2023-31036
7.5 HIGH

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an …

Jan 12, 2024
CVE-2023-28899
4.7 MEDIUM

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service …

Jan 12, 2024
CVE-2024-22494
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-22493
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-22492
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-0460
6.3 MEDIUM

A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/student-print.php. The …

Jan 12, 2024
CVE-2024-0459
4.7 MEDIUM

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. …

Jan 12, 2024
CVE-2023-51978
6.5 MEDIUM

In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.

Jan 12, 2024
CVE-2023-28898
5.3 MEDIUM

The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows …

Jan 12, 2024
CVE-2023-28897
4.0 MEDIUM

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III …

Jan 12, 2024
CVE-2023-51949
8.8 HIGH

Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller

Jan 12, 2024
CVE-2023-49262
9.8 CRITICAL

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Jan 12, 2024
CVE-2023-49261
7.5 HIGH

The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

Jan 12, 2024
CVE-2023-49260
6.1 MEDIUM

An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used together with …

Jan 12, 2024
CVE-2023-49259
7.5 HIGH

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

Jan 12, 2024
CVE-2023-49258
6.1 MEDIUM

User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui/terminal_tool.cgi" in the …

Jan 12, 2024
CVE-2023-49257
8.8 HIGH

An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.

Jan 12, 2024
CVE-2023-49256
7.5 HIGH

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

Jan 12, 2024
CVE-2023-49255
9.8 CRITICAL

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, …

Jan 12, 2024
CVE-2023-49254
8.8 HIGH

Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. …

Jan 12, 2024
CVE-2023-49253
9.8 CRITICAL

Root user password is hardcoded into the device and cannot be changed in the user interface.

Jan 12, 2024
CVE-2023-7028
10.0 CRITICAL KEV

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 …

Jan 12, 2024
CVE-2023-6955
6.6 MEDIUM

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. …

Jan 12, 2024
CVE-2023-5356
7.3 HIGH

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from …

Jan 12, 2024
CVE-2023-4812
7.6 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions …

Jan 12, 2024
CVE-2023-2030
3.5 LOW

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 …

Jan 12, 2024
CVE-2023-0437
5.3 MEDIUM

When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects …

Jan 12, 2024
CVE-2023-52026
9.8 CRITICAL

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

Jan 12, 2024
CVE-2023-51806
5.4 MEDIUM

File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

Jan 12, 2024
CVE-2023-51790
6.1 MEDIUM

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

Jan 12, 2024
CVE-2023-49569
9.8 CRITICAL

A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. …

Jan 12, 2024
CVE-2023-49568
7.5 HIGH

A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to perform denial of service attacks …

Jan 12, 2024
CVE-2023-48909
8.8 HIGH

An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.

Jan 12, 2024
CVE-2023-30016
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.

Jan 12, 2024
CVE-2023-30015
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.