CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-48577
5.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-48504
5.5 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive …

Jan 10, 2024
CVE-2022-47965
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-47915
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-46721
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-46710
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Location data may be …

Jan 10, 2024
CVE-2022-42839
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app …

Jan 10, 2024
CVE-2022-42816
5.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected …

Jan 10, 2024
CVE-2022-32931
5.5 MEDIUM

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to …

Jan 10, 2024
CVE-2022-32919
4.7 MEDIUM

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that …

Jan 10, 2024
CVE-2023-52064
9.8 CRITICAL

Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.

Jan 10, 2024
CVE-2023-51127
7.5 HIGH

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, …

Jan 10, 2024
CVE-2023-51126
9.8 CRITICAL

Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has …

Jan 10, 2024
CVE-2023-29447
5.7 MEDIUM

An insufficiently protected credentials vulnerability in KEPServerEX could allow an adversary to capture user credentials as the web server uses basic authentication.

Jan 10, 2024
CVE-2023-29446
4.7 MEDIUM

An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows …

Jan 10, 2024
CVE-2023-29445
7.8 HIGH

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

Jan 10, 2024
CVE-2022-45793
5.5 MEDIUM

Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution …

Jan 10, 2024
CVE-2023-51195

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 10, 2024
CVE-2023-31488
9.8 CRITICAL

Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, …

Jan 10, 2024
CVE-2023-50916
7.2 HIGH

Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. …

Jan 10, 2024
CVE-2023-48783
5.4 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and …

Jan 10, 2024
CVE-2023-46712
7.2 HIGH

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically …

Jan 10, 2024
CVE-2023-44250
8.8 HIGH

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version …

Jan 10, 2024
CVE-2023-37934
4.3 MEDIUM

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service …

Jan 10, 2024
CVE-2023-37932
6.5 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authenticated attacker …

Jan 10, 2024
CVE-2023-29444
6.3 MEDIUM

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they …

Jan 10, 2024
CVE-2023-51970
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51969
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.

Jan 10, 2024
CVE-2023-51968
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.

Jan 10, 2024
CVE-2023-51967
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.

Jan 10, 2024
CVE-2023-51962
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-50172
5.3 MEDIUM

A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-49864
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49863
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49862
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49810
7.3 HIGH

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49738
7.5 HIGH

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary …

Jan 10, 2024
CVE-2023-49715
4.3 MEDIUM

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-49599
9.8 CRITICAL

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can …

Jan 10, 2024
CVE-2023-49589
8.8 HIGH

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-48730
8.5 HIGH

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-48728
9.6 CRITICAL

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-47862
9.8 CRITICAL

A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to …

Jan 10, 2024
CVE-2023-47861
9.0 CRITICAL

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP …

Jan 10, 2024
CVE-2023-47171
6.5 MEDIUM

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request …

Jan 10, 2024
CVE-2023-45139
7.5 HIGH

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker …

Jan 10, 2024
CVE-2023-41056
8.1 HIGH

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to …

Jan 10, 2024
CVE-2023-6158
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a …

Jan 10, 2024
CVE-2023-51965
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51964
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.