CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21982
4.8 MEDIUM

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when …

Jan 12, 2024
CVE-2024-0443
5.5 MEDIUM

A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a …

Jan 12, 2024
CVE-2023-51350
9.8 CRITICAL

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For …

Jan 11, 2024
CVE-2024-21337
5.2 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 11, 2024
CVE-2023-46474
7.2 HIGH

File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php …

Jan 11, 2024
CVE-2024-20675
6.3 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Jan 11, 2024
CVE-2024-0426
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2023-7226
6.3 MEDIUM

A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of …

Jan 11, 2024
CVE-2023-50129
6.5 MEDIUM

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024
CVE-2023-50128
5.3 MEDIUM

The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker …

Jan 11, 2024
CVE-2023-50127
5.9 MEDIUM

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an …

Jan 11, 2024
CVE-2023-50126
6.5 MEDIUM

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024
CVE-2023-50125
5.9 MEDIUM

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

Jan 11, 2024
CVE-2023-50124
6.8 MEDIUM

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design …

Jan 11, 2024
CVE-2023-50123
8.1 HIGH

The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state is not limited. This could allow an attacker to …

Jan 11, 2024
CVE-2022-4959
3.5 LOW

A vulnerability classified as problematic was found in qkmc-rk redbbs 1.0. Affected by this vulnerability is an unknown functionality of the component Nickname Handler. The …

Jan 11, 2024
CVE-2024-22198
7.1 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` …

Jan 11, 2024
CVE-2024-22196
7.0 HIGH

Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to …

Jan 11, 2024
CVE-2024-0425
5.3 MEDIUM

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads …

Jan 11, 2024
CVE-2024-0424
3.5 LOW

A vulnerability classified as problematic has been found in CodeAstro Simple Banking System 1.0. This affects an unknown part of the file createuser.php of the …

Jan 11, 2024
CVE-2024-0423
3.5 LOW

A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jan 11, 2024
CVE-2024-0227

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 11, 2024
CVE-2024-0422
3.5 LOW

A vulnerability was found in CodeAstro POS and Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown …

Jan 11, 2024
CVE-2024-0419
5.3 MEDIUM

A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST …

Jan 11, 2024
CVE-2023-51782
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.

Jan 11, 2024
CVE-2023-51781
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.

Jan 11, 2024
CVE-2023-51780
7.0 HIGH

An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.

Jan 11, 2024
CVE-2024-22199
9.3 CRITICAL

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications …

Jan 11, 2024
CVE-2024-22197
7.7 HIGH

Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes …

Jan 11, 2024
CVE-2024-0418
5.3 MEDIUM

A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of …

Jan 11, 2024
CVE-2024-0417
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The …

Jan 11, 2024
CVE-2024-0416
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of …

Jan 11, 2024
CVE-2024-0415
6.3 MEDIUM

A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php …

Jan 11, 2024
CVE-2024-0414
5.3 MEDIUM

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation …

Jan 11, 2024
CVE-2024-0413
5.3 MEDIUM

A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2024-0412
5.3 MEDIUM

A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file public/install.php …

Jan 11, 2024
CVE-2024-0411
5.3 MEDIUM

A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php …

Jan 11, 2024
CVE-2023-50671
7.8 HIGH

In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.

Jan 11, 2024
CVE-2024-23061
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.

Jan 11, 2024
CVE-2024-23060
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg function.

Jan 11, 2024
CVE-2024-23059
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnsCfg function.

Jan 11, 2024
CVE-2024-23058
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.

Jan 11, 2024
CVE-2024-23057
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg function.

Jan 11, 2024
CVE-2024-22942
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanCfg function.

Jan 11, 2024
CVE-2024-0429
7.3 HIGH

A denial service vulnerability has been found on Hex Workshop affecting version 6.7, an attacker could send a command line file arguments and control the …

Jan 11, 2024
CVE-2023-6554
6.5 MEDIUM

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to …

Jan 11, 2024
CVE-2023-5118
5.4 MEDIUM

The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author …

Jan 11, 2024
CVE-2023-51989

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-51987. Reason: This candidate is a reservation duplicate of CVE-2025-51987. Notes: All CVE users should reference …

Jan 11, 2024
CVE-2023-51987
9.8 CRITICAL

D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords.

Jan 11, 2024
CVE-2023-51984
9.8 CRITICAL

D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. allows remote attackers to execute arbitrary commands via shell.

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.