CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49556
5.5 MEDIUM

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

Jan 3, 2024
CVE-2023-49555
5.5 MEDIUM

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49554
5.5 MEDIUM

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

Jan 3, 2024
CVE-2023-49553
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.

Jan 2, 2024
CVE-2023-49552
7.5 HIGH

An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the …

Jan 2, 2024
CVE-2023-49551
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.

Jan 2, 2024
CVE-2023-49550
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

Jan 2, 2024
CVE-2023-49549
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.

Jan 2, 2024
CVE-2023-48418
10.0 CRITICAL

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to …

Jan 2, 2024
CVE-2024-21632
8.6 HIGH

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute …

Jan 2, 2024
CVE-2024-21629
5.9 MEDIUM

Rust EVM is an Ethereum Virtual Machine interpreter. In `rust-evm`, a feature called `record_external_operation` was introduced, allowing library users to record custom gas changes. This …

Jan 2, 2024
CVE-2024-21628
5.4 MEDIUM

PrestaShop is an open-source e-commerce platform. Prior to version 8.1.3, the isCleanHtml method is not used on this this form, which makes it possible to …

Jan 2, 2024
CVE-2024-0196
6.3 MEDIUM

A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 2, 2024
CVE-2023-6339
10.0 CRITICAL

Google Nest WiFi Pro root code-execution & user-data compromise

Jan 2, 2024
CVE-2023-50020
7.5 HIGH

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Jan 2, 2024
CVE-2023-50019
5.9 MEDIUM

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration …

Jan 2, 2024
CVE-2023-4164
8.4 HIGH

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional …

Jan 2, 2024
CVE-2020-26625
3.8 LOW

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' …

Jan 2, 2024
CVE-2020-26624
3.8 LOW

A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID …

Jan 2, 2024
CVE-2020-26623
3.8 LOW

SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the …

Jan 2, 2024
CVE-2024-21627
8.1 HIGH

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using …

Jan 2, 2024
CVE-2024-21623
9.8 CRITICAL

OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarCloud`" workflow is vulnerable to an expression injection in …

Jan 2, 2024
CVE-2024-0195
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to …

Jan 2, 2024
CVE-2024-0194
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of …

Jan 2, 2024
CVE-2023-47458
9.8 CRITICAL

An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

Jan 2, 2024
CVE-2023-45893
7.5 HIGH

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive …

Jan 2, 2024
CVE-2023-45892
7.5 HIGH

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

Jan 2, 2024
CVE-2023-45561
5.3 MEDIUM

An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

Jan 2, 2024
CVE-2024-0192
6.3 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jan 2, 2024
CVE-2024-0191
5.3 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the …

Jan 2, 2024
CVE-2023-51652
6.1 MEDIUM

OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0, there is a potential for a …

Jan 2, 2024
CVE-2023-50711
5.7 MEDIUM

vmm-sys-util is a collection of modules that provides helpers and utilities used by multiple rust-vmm components. Starting in version 0.5.0 and prior to version 0.12.0, …

Jan 2, 2024
CVE-2023-49794
6.7 MEDIUM

KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in KernelSU kernel module can …

Jan 2, 2024
CVE-2024-0190
3.5 LOW

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file …

Jan 2, 2024
CVE-2023-7192
5.5 MEDIUM

A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to …

Jan 2, 2024
CVE-2023-48419
10.0 CRITICAL

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege

Jan 2, 2024
CVE-2022-3010
7.5 HIGH

The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate …

Jan 2, 2024
CVE-2024-0193
7.8 HIGH

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, …

Jan 2, 2024
CVE-2024-0189
3.5 LOW

A vulnerability has been found in RRJ Nueva Ecija Engineer Online Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file …

Jan 2, 2024
CVE-2023-4280
9.3 CRITICAL

An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of …

Jan 2, 2024
CVE-2023-48721

Rejected reason: Not used

Jan 2, 2024
CVE-2018-25097
3.5 LOW

A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to …

Jan 2, 2024
CVE-2024-0188
3.1 LOW

A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file …

Jan 2, 2024
CVE-2017-20188
2.6 LOW

A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the …

Jan 2, 2024
CVE-2015-10128
3.5 LOW

A vulnerability was found in rt-prettyphoto Plugin up to 1.2 on WordPress and classified as problematic. Affected by this issue is the function royal_prettyphoto_plugin_links of …

Jan 2, 2024
CVE-2023-6436
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection.This issue affects Website Template: …

Jan 2, 2024
CVE-2023-6693
4.9 MEDIUM

A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest …

Jan 2, 2024
CVE-2023-50333
3.7 LOW

Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change …

Jan 2, 2024
CVE-2023-48732
4.3 MEDIUM

Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was …

Jan 2, 2024
CVE-2023-47858
4.3 MEDIUM

Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived …

Jan 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.