CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52311
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-52310
9.6 CRITICAL

PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

Jan 3, 2024
CVE-2023-52309
8.2 HIGH

Heap buffer overflow in paddle.repeat_interleave in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, information disclosure, or more damage is possible.

Jan 3, 2024
CVE-2023-52308
4.7 MEDIUM

FPE in paddle.amin in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52307
8.2 HIGH

Stack overflow in paddle.linalg.lu_unpack in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2023-52306
4.7 MEDIUM

FPE in paddle.lerp in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52305
4.7 MEDIUM

FPE in paddle.topk in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52304
8.2 HIGH

Stack overflow in paddle.searchsorted in PaddlePaddle before 2.6.0. This flaw can lead to a denial of service, or even more damage.

Jan 3, 2024
CVE-2023-52303
4.7 MEDIUM

Nullptr in paddle.put_along_axis in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-52302
4.7 MEDIUM

Nullptr in paddle.nextafter in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-50921
9.8 CRITICAL

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects …

Jan 3, 2024
CVE-2023-38678
4.7 MEDIUM

OOB access in paddle.mode in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38677
4.7 MEDIUM

FPE in paddle.linalg.eig in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38676
4.7 MEDIUM

Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38675
4.7 MEDIUM

FPE in paddle.linalg.matrix_rank in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2023-38674
4.7 MEDIUM

FPE in paddle.nanmedian in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.

Jan 3, 2024
CVE-2024-0211
7.8 HIGH

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0210
7.8 HIGH

Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0209
7.8 HIGH

IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0208
7.8 HIGH

GVCP dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2024-0207
7.8 HIGH

HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

Jan 3, 2024
CVE-2023-50922
7.2 HIGH

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a …

Jan 3, 2024
CVE-2023-6986
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Jan 3, 2024
CVE-2023-47473
7.5 HIGH

Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.

Jan 3, 2024
CVE-2023-6981
6.1 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to SQL Injection via the 'group_id' parameter …

Jan 3, 2024
CVE-2023-6980
4.3 MEDIUM

The WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Jan 3, 2024
CVE-2023-6600
8.6 HIGH

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to …

Jan 3, 2024
CVE-2023-6524
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the map title parameter in all versions up to and …

Jan 3, 2024
CVE-2023-42358
7.7 HIGH

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a …

Jan 3, 2024
CVE-2023-7027
7.2 HIGH

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 3, 2024
CVE-2023-6629
6.1 MEDIUM

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting …

Jan 3, 2024
CVE-2023-46308
9.8 CRITICAL

In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

Jan 3, 2024
CVE-2023-50344
5.4 MEDIUM

HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.

Jan 3, 2024
CVE-2023-50343
8.3 HIGH

HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow …

Jan 3, 2024
CVE-2023-50342
7.1 HIGH

HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certain details about another user as a result …

Jan 3, 2024
CVE-2023-50341
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" …

Jan 3, 2024
CVE-2023-45724
8.2 HIGH

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

Jan 3, 2024
CVE-2023-45723
7.6 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file …

Jan 3, 2024
CVE-2023-45722
8.8 HIGH

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to …

Jan 3, 2024
CVE-2023-50351
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity …

Jan 3, 2024
CVE-2023-50350
8.2 HIGH

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

Jan 3, 2024
CVE-2023-50348
3.1 LOW

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into …

Jan 3, 2024
CVE-2023-50346
3.1 LOW

HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information.

Jan 3, 2024
CVE-2023-50345
3.7 LOW

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing …

Jan 3, 2024
CVE-2023-41783
4.3 MEDIUM

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit …

Jan 3, 2024
CVE-2023-41780
6.4 MEDIUM

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could …

Jan 3, 2024
CVE-2023-41779
4.4 MEDIUM

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the …

Jan 3, 2024
CVE-2023-41776
6.7 MEDIUM

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

Jan 3, 2024
CVE-2023-49558
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49557
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

Jan 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.