CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-30014
9.8 CRITICAL

SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.

Jan 12, 2024
CVE-2023-6740
8.8 HIGH

Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-6735
8.8 HIGH

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Jan 12, 2024
CVE-2023-50920
5.5 MEDIUM

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session …

Jan 12, 2024
CVE-2023-50919
9.8 CRITICAL

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, …

Jan 12, 2024
CVE-2023-40362
4.3 MEDIUM

An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors …

Jan 12, 2024
CVE-2023-31211
8.8 HIGH

Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials

Jan 12, 2024
CVE-2024-22027
6.5 MEDIUM

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack …

Jan 12, 2024
CVE-2023-37117
9.8 CRITICAL

A heap-use-after-free vulnerability was found in live555 version 2023.05.10 while handling the SETUP.

Jan 12, 2024
CVE-2023-34061
7.5 HIGH

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route …

Jan 12, 2024
CVE-2024-23179
6.1 MEDIUM

An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This …

Jan 12, 2024
CVE-2024-23178
5.4 MEDIUM

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

Jan 12, 2024
CVE-2024-23177
6.1 MEDIUM

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

Jan 12, 2024
CVE-2024-0393

Rejected reason: This CVE ID was unused by the CNA.

Jan 12, 2024
CVE-2024-23174
5.4 MEDIUM

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23173
6.1 MEDIUM

An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows …

Jan 12, 2024
CVE-2024-23172
5.4 MEDIUM

An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23171
5.4 MEDIUM

An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows …

Jan 12, 2024
CVE-2022-4961
5.5 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 12, 2024
CVE-2022-48620
9.8 CRITICAL

uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.

Jan 12, 2024
CVE-2022-4960
3.5 LOW

A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component …

Jan 12, 2024
CVE-2022-48619
5.5 MEDIUM

An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the …

Jan 12, 2024
CVE-2016-20021
9.8 CRITICAL

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature …

Jan 12, 2024
CVE-2024-0454
6.0 MEDIUM

ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows …

Jan 12, 2024
CVE-2023-6040
7.8 HIGH

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, …

Jan 12, 2024
CVE-2023-52339
6.5 MEDIUM

In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.

Jan 12, 2024
CVE-2023-40250
8.8 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893.

Jan 12, 2024
CVE-2024-21617
6.5 MEDIUM

An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading …

Jan 12, 2024
CVE-2024-21616
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jan 12, 2024
CVE-2024-21614
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a …

Jan 12, 2024
CVE-2024-21613
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Jan 12, 2024
CVE-2024-21612
7.5 HIGH

An Improper Handling of Syntactically Invalid Structure vulnerability in Object Flooding Protocol (OFP) service of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker …

Jan 12, 2024
CVE-2024-21611
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jan 12, 2024
CVE-2024-21607
5.3 MEDIUM

An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024
CVE-2024-21606
7.5 HIGH

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause …

Jan 12, 2024
CVE-2024-21604
7.5 HIGH

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024
CVE-2024-21603
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker …

Jan 12, 2024
CVE-2024-21602
7.5 HIGH

A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial …

Jan 12, 2024
CVE-2024-21601
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series …

Jan 12, 2024
CVE-2024-21600
6.5 MEDIUM

An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, …

Jan 12, 2024
CVE-2024-21599
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21597
5.3 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, …

Jan 12, 2024
CVE-2024-21596
5.3 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based …

Jan 12, 2024
CVE-2024-21595
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker …

Jan 12, 2024
CVE-2024-21594
5.5 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a …

Jan 12, 2024
CVE-2024-21591
9.8 CRITICAL

An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a …

Jan 12, 2024
CVE-2024-21589
7.4 HIGH

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially …

Jan 12, 2024
CVE-2024-21587
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21585
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, …

Jan 12, 2024
CVE-2023-36842
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to …

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.