CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50120
5.5 MEDIUM

MP4Box GPAC version 2.3-DEV-rev636-gfbd7e13aa-master was discovered to contain an infinite loop in the function av1_uvlc at media_tools/av_parsers.c. This vulnerability allows attackers to cause a Denial …

Jan 10, 2024
CVE-2023-49619
3.1 LOW

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a …

Jan 10, 2024
CVE-2023-49471
8.8 HIGH

Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which …

Jan 10, 2024
CVE-2023-49427
7.5 HIGH

Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

Jan 10, 2024
CVE-2023-49394
6.1 MEDIUM

Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

Jan 10, 2024
CVE-2020-26630
4.9 MEDIUM

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload …

Jan 10, 2024
CVE-2020-26629
9.8 CRITICAL

A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the …

Jan 10, 2024
CVE-2020-26628
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via …

Jan 10, 2024
CVE-2020-26627
4.9 MEDIUM

A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload …

Jan 10, 2024
CVE-2023-48864
7.5 HIGH

SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.

Jan 10, 2024
CVE-2023-41603
5.3 MEDIUM

D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the …

Jan 10, 2024
CVE-2022-46025
9.1 CRITICAL

Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi system information, such as Wi-Fi SSID and Wi-Fi …

Jan 10, 2024
CVE-2023-41781
5.7 MEDIUM

There is a Cross-site scripting (XSS) vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

Jan 10, 2024
CVE-2024-21643
7.1 HIGH

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol …

Jan 10, 2024
CVE-2024-0364
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The …

Jan 10, 2024
CVE-2024-0363
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 10, 2024
CVE-2024-0362
5.5 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. …

Jan 10, 2024
CVE-2024-0361
5.5 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation …

Jan 10, 2024
CVE-2023-31446
9.8 CRITICAL

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with …

Jan 10, 2024
CVE-2024-0360
5.5 MEDIUM

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jan 10, 2024
CVE-2024-0359
7.3 HIGH

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 10, 2024
CVE-2024-0358
5.3 MEDIUM

A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. …

Jan 10, 2024
CVE-2024-0357
5.5 MEDIUM

A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of …

Jan 10, 2024
CVE-2024-0356
4.3 MEDIUM

A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles …

Jan 10, 2024
CVE-2024-0355
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of …

Jan 10, 2024
CVE-2024-0354
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file …

Jan 10, 2024
CVE-2023-47997
6.5 MEDIUM

An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.

Jan 10, 2024
CVE-2024-0352
7.3 HIGH

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component …

Jan 9, 2024
CVE-2024-0351
3.1 LOW

A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. …

Jan 9, 2024
CVE-2024-0350
3.1 LOW

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The …

Jan 9, 2024
CVE-2024-0349
3.7 LOW

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The …

Jan 9, 2024
CVE-2023-47996
6.5 MEDIUM

An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.

Jan 9, 2024
CVE-2023-47995
6.5 MEDIUM

Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.

Jan 9, 2024
CVE-2023-47994
8.8 HIGH

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run …

Jan 9, 2024
CVE-2023-47993
6.5 MEDIUM

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

Jan 9, 2024
CVE-2023-47992
8.8 HIGH

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

Jan 9, 2024
CVE-2023-3043
9.6 CRITICAL

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37297
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37296
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37295
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37294
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37293
9.6 CRITICAL

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-34333
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-34332
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation …

Jan 9, 2024
CVE-2024-0348
4.3 MEDIUM

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the component File …

Jan 9, 2024
CVE-2024-0347
3.7 LOW

A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The …

Jan 9, 2024
CVE-2024-0346
3.5 LOW

A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php of …

Jan 9, 2024
CVE-2023-6476
6.5 MEDIUM

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and …

Jan 9, 2024
CVE-2023-5770
5.3 MEDIUM

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body …

Jan 9, 2024
CVE-2023-50136
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table.

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.