CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32875
4.4 MEDIUM

In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges …

Jan 2, 2024
CVE-2023-32874
9.8 CRITICAL

In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jan 2, 2024
CVE-2023-32872
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Jan 2, 2024
CVE-2023-32831
5.5 MEDIUM

In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no …

Jan 2, 2024
CVE-2024-0186
3.7 LOW

A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 …

Jan 2, 2024
CVE-2024-0185
4.7 MEDIUM

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affects some unknown processing of …

Jan 2, 2024
CVE-2024-0184
2.4 LOW

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

Jan 2, 2024
CVE-2024-0183
2.4 LOW

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. This affects an unknown part of the …

Jan 1, 2024
CVE-2024-0182
7.3 HIGH

A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jan 1, 2024
CVE-2023-50096
7.5 HIGH

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This …

Jan 1, 2024
CVE-2023-50094
8.8 HIGH

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The …

Jan 1, 2024
CVE-2024-0181
2.4 LOW

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown …

Jan 1, 2024
CVE-2023-6485
5.4 MEDIUM

The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around …

Jan 1, 2024
CVE-2023-6421
7.5 HIGH

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

Jan 1, 2024
CVE-2023-6271
7.5 HIGH

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak …

Jan 1, 2024
CVE-2023-6113
7.5 HIGH

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information …

Jan 1, 2024
CVE-2023-6064
7.5 HIGH

The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

Jan 1, 2024
CVE-2023-6037
4.8 MEDIUM

The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 1, 2024
CVE-2023-6000
6.1 MEDIUM

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead …

Jan 1, 2024
CVE-2023-5877
9.8 CRITICAL

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, …

Jan 1, 2024
CVE-2024-21732
6.1 MEDIUM

FlyCms through abbaa5a allows XSS via the permission management feature.

Jan 1, 2024
CVE-2008-1247

The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary …

Mar 10, 2008
CVE-2006-5202

Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to …

Oct 10, 2006

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.