CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6148
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-50974
5.5 MEDIUM

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as …

Jan 9, 2024
CVE-2023-50585
9.8 CRITICAL

Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

Jan 9, 2024
CVE-2023-49237
9.8 CRITICAL

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language …

Jan 9, 2024
CVE-2023-49236
9.8 CRITICAL

A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation …

Jan 9, 2024
CVE-2023-49235
9.8 CRITICAL

An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker …

Jan 9, 2024
CVE-2023-7220
9.8 CRITICAL

A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The …

Jan 9, 2024
CVE-2023-6147
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-6842
4.4 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 9, 2024
CVE-2023-6830
6.5 MEDIUM

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject …

Jan 9, 2024
CVE-2023-50932
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50931
8.3 HIGH

An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-50930
8.3 HIGH

An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be …

Jan 9, 2024
CVE-2023-7219
7.2 HIGH

A vulnerability has been found in Totolink N350RT 9.3.5u.6139_B202012 and classified as critical. Affected by this vulnerability is the function loginAuth of the file /cgi-bin/cstecgi.cgi. …

Jan 9, 2024
CVE-2023-6788
5.4 MEDIUM

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is …

Jan 9, 2024
CVE-2023-6594
4.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 …

Jan 9, 2024
CVE-2024-22125
7.4 HIGH

Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allows an attacker to access highly sensitive information …

Jan 9, 2024
CVE-2024-22124
4.1 MEDIUM

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, …

Jan 9, 2024
CVE-2024-21738
4.1 MEDIUM

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges …

Jan 9, 2024
CVE-2024-21737
8.4 HIGH

In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and …

Jan 9, 2024
CVE-2024-21736
6.4 MEDIUM

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered …

Jan 9, 2024
CVE-2023-51717
9.8 CRITICAL

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

Jan 9, 2024
CVE-2023-49238
9.8 CRITICAL

In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a …

Jan 9, 2024
CVE-2023-39336
8.8 HIGH

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to …

Jan 9, 2024
CVE-2023-36629
5.5 MEDIUM

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

Jan 9, 2024
CVE-2023-27098
7.5 HIGH

TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

Jan 9, 2024
CVE-2023-27000
6.1 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion …

Jan 9, 2024
CVE-2023-26999
9.8 CRITICAL

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

Jan 9, 2024
CVE-2023-26998
5.4 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

Jan 9, 2024
CVE-2024-21735
7.3 HIGH

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This …

Jan 9, 2024
CVE-2024-21734
3.7 LOW

SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to …

Jan 9, 2024
CVE-2024-21646
9.8 CRITICAL

Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When …

Jan 9, 2024
CVE-2023-50643
9.8 CRITICAL

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

Jan 9, 2024
CVE-2023-46906
4.9 MEDIUM

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone …

Jan 9, 2024
CVE-2024-21663
9.9 CRITICAL

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote …

Jan 9, 2024
CVE-2024-21651
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to …

Jan 9, 2024
CVE-2024-21648
8.0 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, …

Jan 9, 2024
CVE-2023-50162
7.2 HIGH

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

Jan 9, 2024
CVE-2023-52074
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.

Jan 8, 2024
CVE-2023-52073
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.

Jan 8, 2024
CVE-2023-52072
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.

Jan 8, 2024
CVE-2022-40696
3.7 LOW

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This issue affects Advanced Custom Fields (ACF): from 3.1.1 through …

Jan 8, 2024
CVE-2022-36352
6.3 MEDIUM

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a …

Jan 8, 2024
CVE-2022-34344
5.4 MEDIUM

Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This …

Jan 8, 2024
CVE-2022-29409

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 8, 2024
CVE-2023-7218
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2023-52202
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist …

Jan 8, 2024
CVE-2023-52201
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.

Jan 8, 2024
CVE-2023-52198
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google …

Jan 8, 2024
CVE-2023-52197
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.