CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22047
3.1 LOW

A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to …

Jan 4, 2024
CVE-2024-0241
7.5 HIGH

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by …

Jan 4, 2024
CVE-2024-21636
6.1 MEDIUM

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. Versions prior to 3.9.0 and 2.83.0 have a cross-site …

Jan 4, 2024
CVE-2023-51812
9.8 CRITICAL

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

Jan 4, 2024
CVE-2023-51154
9.8 CRITICAL

Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

Jan 4, 2024
CVE-2023-6270
7.0 HIGH

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, …

Jan 4, 2024
CVE-2023-6551
5.4 MEDIUM

As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. …

Jan 4, 2024
CVE-2024-21625
8.8 HIGH

SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to …

Jan 4, 2024
CVE-2023-50867
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50866
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50865
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50864
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50863
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50862
9.8 CRITICAL

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-50760
8.8 HIGH

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to …

Jan 4, 2024
CVE-2023-3726
6.9 MEDIUM

OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

Jan 4, 2024
CVE-2023-50753
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50752
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-50743
9.8 CRITICAL

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters …

Jan 4, 2024
CVE-2023-49666
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49665
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49658
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49639
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49633
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49625
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49624
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-49622
9.8 CRITICAL

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and …

Jan 4, 2024
CVE-2023-6992
4.0 MEDIUM

Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper …

Jan 4, 2024
CVE-2021-45465
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-42028
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could …

Jan 4, 2024
CVE-2021-40367
7.8 HIGH

A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could …

Jan 4, 2024
CVE-2023-7044
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom …

Jan 4, 2024
CVE-2023-6944
5.7 MEDIUM

A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded …

Jan 4, 2024
CVE-2022-3864
4.5 MEDIUM

A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED to restart. After restart the device is …

Jan 4, 2024
CVE-2022-2081
7.5 HIGH

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, …

Jan 4, 2024
CVE-2023-50630
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in xiweicheng TMS v.2.28.0 allows a remote attacker to execute arbitrary code via a crafted script to the click here …

Jan 4, 2024
CVE-2023-50082
7.5 HIGH

Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid …

Jan 4, 2024
CVE-2023-41784
6.6 MEDIUM

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

Jan 4, 2024
CVE-2023-52322
6.1 MEDIUM

ecrire/public/assembler.php in SPIP before 4.1.13 and 4.2.x before 4.2.7 allows XSS because input from _request() is not restricted to safe characters such as alphanumerics.

Jan 4, 2024
CVE-2022-43375

Rejected reason: This CVE ID was unused by the CNA.

Jan 4, 2024
CVE-2023-29962
6.5 MEDIUM

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

Jan 4, 2024
CVE-2023-6738
5.4 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' …

Jan 4, 2024
CVE-2023-6733
6.5 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. …

Jan 4, 2024
CVE-2023-6498
4.4 MEDIUM

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including …

Jan 4, 2024
CVE-2024-0225
8.8 HIGH

Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0224
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0223
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 4, 2024
CVE-2024-0222
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Jan 4, 2024
CVE-2024-20809
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024
CVE-2024-20808
4.0 MEDIUM

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Jan 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.