CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20807
3.3 LOW

Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.

Jan 4, 2024
CVE-2024-20806
6.2 MEDIUM

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

Jan 4, 2024
CVE-2024-20805
3.3 LOW

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20804
4.0 MEDIUM

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 …

Jan 4, 2024
CVE-2024-20803
6.8 MEDIUM

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

Jan 4, 2024
CVE-2024-20802
4.6 MEDIUM

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

Jan 4, 2024
CVE-2024-21634
7.5 HIGH

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for applications that …

Jan 3, 2024
CVE-2023-5138
6.8 MEDIUM

Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.

Jan 3, 2024
CVE-2023-50256
7.5 HIGH

Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registration form with the essential fields, such as …

Jan 3, 2024
CVE-2023-6540
6.5 MEDIUM

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload …

Jan 3, 2024
CVE-2023-6338
7.8 HIGH

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with …

Jan 3, 2024
CVE-2023-49442
9.8 CRITICAL

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Jan 3, 2024
CVE-2023-5881
8.2 HIGH

Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's …

Jan 3, 2024
CVE-2023-5880
8.8 HIGH

When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” …

Jan 3, 2024
CVE-2023-5879
6.8 MEDIUM

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on …

Jan 3, 2024
CVE-2023-50090
9.8 CRITICAL

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted …

Jan 3, 2024
CVE-2023-46929
7.5 HIGH

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the application.

Jan 3, 2024
CVE-2024-21633
7.8 HIGH

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource …

Jan 3, 2024
CVE-2024-21631
6.5 MEDIUM

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may …

Jan 3, 2024
CVE-2024-21622
5.4 MEDIUM

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 …

Jan 3, 2024
CVE-2024-0217
3.3 LOW

A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some …

Jan 3, 2024
CVE-2023-6004
4.8 MEDIUM

A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may …

Jan 3, 2024
CVE-2023-50253
9.6 CRITICAL

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without …

Jan 3, 2024
CVE-2023-46742
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the …

Jan 3, 2024
CVE-2023-46741
4.8 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive …

Jan 3, 2024
CVE-2023-46740
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used …

Jan 3, 2024
CVE-2023-46739
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could …

Jan 3, 2024
CVE-2024-21911
6.1 MEDIUM

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21910
6.1 MEDIUM

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would …

Jan 3, 2024
CVE-2024-21909
7.5 HIGH

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted …

Jan 3, 2024
CVE-2024-21908
6.1 MEDIUM

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting …

Jan 3, 2024
CVE-2024-21907
7.5 HIGH

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a …

Jan 3, 2024
CVE-2023-46738
6.5 MEDIUM

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated …

Jan 3, 2024
CVE-2023-30617
6.5 MEDIUM

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has …

Jan 3, 2024
CVE-2023-45559
8.2 HIGH

An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 3, 2024
CVE-2023-50093
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.

Jan 3, 2024
CVE-2023-37607
7.5 HIGH

Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the …

Jan 3, 2024
CVE-2023-50092
6.1 MEDIUM

APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).

Jan 3, 2024
CVE-2023-39655
9.6 CRITICAL

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password …

Jan 3, 2024
CVE-2023-37608
7.5 HIGH

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin …

Jan 3, 2024
CVE-2024-0201
5.4 MEDIUM

The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function …

Jan 3, 2024
CVE-2023-51785
7.5 HIGH

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack …

Jan 3, 2024
CVE-2023-51784
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote …

Jan 3, 2024
CVE-2023-7068
4.3 MEDIUM

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Jan 3, 2024
CVE-2023-6984
5.3 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Jan 3, 2024
CVE-2023-6747
6.4 MEDIUM

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom attributes in all versions up to, …

Jan 3, 2024
CVE-2023-6621
6.1 MEDIUM

The POST SMTP WordPress plugin before 2.8.7 does not sanitise and escape the msg parameter before outputting it back in the page, leading to a …

Jan 3, 2024
CVE-2023-52314
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-52313
4.7 MEDIUM

FPE in paddle.argmin and paddle.argmax in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52312
4.7 MEDIUM

Nullptr dereference in paddle.crop in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.