CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51963
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51960
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51959
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51958
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51957
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

Jan 10, 2024
CVE-2023-51956
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv

Jan 10, 2024
CVE-2023-51955
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51954
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51953
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

Jan 10, 2024
CVE-2023-51952
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

Jan 10, 2024
CVE-2024-0395

Rejected reason: NON Security Issue.

Jan 10, 2024
CVE-2024-0389
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The …

Jan 10, 2024
CVE-2023-51966
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

Jan 10, 2024
CVE-2023-51961
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

Jan 10, 2024
CVE-2024-20715
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20714
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20713
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20712
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20711
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2024-20710
5.5 MEDIUM

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jan 10, 2024
CVE-2023-5455
6.5 MEDIUM

A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting …

Jan 10, 2024
CVE-2023-51972
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

Jan 10, 2024
CVE-2023-51971
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.

Jan 10, 2024
CVE-2023-48266
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48265
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48264
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48263
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48262
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48261
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48260
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48259
5.3 MEDIUM

The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48258
5.5 MEDIUM

The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.

Jan 10, 2024
CVE-2023-48257
7.8 HIGH

The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on …

Jan 10, 2024
CVE-2023-48256
5.3 MEDIUM

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL …

Jan 10, 2024
CVE-2023-48255
6.3 MEDIUM

The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session …

Jan 10, 2024
CVE-2023-48254
5.3 MEDIUM

The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

Jan 10, 2024
CVE-2023-48253
8.8 HIGH

The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this …

Jan 10, 2024
CVE-2023-48252
8.8 HIGH

The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

Jan 10, 2024
CVE-2023-48251
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

Jan 10, 2024
CVE-2024-0310
6.1 MEDIUM

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to …

Jan 10, 2024
CVE-2023-48250
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

Jan 10, 2024
CVE-2023-48249
6.5 MEDIUM

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user …

Jan 10, 2024
CVE-2023-48248
5.5 MEDIUM

The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution …

Jan 10, 2024
CVE-2023-48247
5.3 MEDIUM

The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48246
6.5 MEDIUM

The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) …

Jan 10, 2024
CVE-2023-48245
6.5 MEDIUM

The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.

Jan 10, 2024
CVE-2023-48244
5.3 MEDIUM

The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request.

Jan 10, 2024
CVE-2023-48243
8.1 HIGH

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) …

Jan 10, 2024
CVE-2023-48242
6.5 MEDIUM

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user …

Jan 10, 2024
CVE-2023-51252
5.4 MEDIUM

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.