CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22237
7.8 HIGH

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2023-40545
8.8 HIGH

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

Feb 6, 2024
CVE-2023-47618
7.2 HIGH

A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-47617
7.2 HIGH

A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A …

Feb 6, 2024
CVE-2023-47209
7.2 HIGH

A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-47167
7.2 HIGH

A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-46683
7.2 HIGH

A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A …

Feb 6, 2024
CVE-2023-43482
7.2 HIGH

A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP …

Feb 6, 2024
CVE-2023-42664
7.2 HIGH

A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. …

Feb 6, 2024
CVE-2023-36498
7.2 HIGH

A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted …

Feb 6, 2024
CVE-2023-50395
8.0 HIGH

SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

Feb 6, 2024
CVE-2023-35188
8.0 HIGH

SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

Feb 6, 2024
CVE-2024-24591
8.0 HIGH

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write …

Feb 6, 2024
CVE-2024-24590
8.0 HIGH

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact …

Feb 6, 2024
CVE-2024-23673
8.5 HIGH

Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. …

Feb 6, 2024
CVE-2023-32451
7.3 HIGH

Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation

Feb 6, 2024
CVE-2024-22433
8.8 HIGH

Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated …

Feb 6, 2024
CVE-2023-25543
7.8 HIGH

Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability …

Feb 6, 2024
CVE-2023-43536
7.5 HIGH

Transient DOS while parse fils IE with length equal to 1.

Feb 6, 2024
CVE-2023-43535
8.4 HIGH

Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.

Feb 6, 2024
CVE-2023-43534
8.6 HIGH

Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

Feb 6, 2024
CVE-2023-43533
7.5 HIGH

Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

Feb 6, 2024
CVE-2023-43532
8.4 HIGH

Memory corruption while reading ACPI config through the user mode app.

Feb 6, 2024
CVE-2023-43523
7.5 HIGH

Transient DOS while processing 11AZ RTT management action frame received through OTA.

Feb 6, 2024
CVE-2023-43522
7.5 HIGH

Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

Feb 6, 2024
CVE-2023-43520
8.6 HIGH

Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.

Feb 6, 2024
CVE-2023-43519
7.3 HIGH

Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

Feb 6, 2024
CVE-2023-43518
7.3 HIGH

Memory corruption in video while parsing invalid mp2 clip.

Feb 6, 2024
CVE-2023-43517
8.4 HIGH

Memory corruption in Automotive Multimedia due to improper access control in HAB.

Feb 6, 2024
CVE-2023-43516
7.8 HIGH

Memory corruption when malformed message payload is received from firmware.

Feb 6, 2024
CVE-2023-43513
7.8 HIGH

Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point …

Feb 6, 2024
CVE-2023-33060
7.1 HIGH

Transient DOS in Core when DDR memory check is called while DDR is not initialized.

Feb 6, 2024
CVE-2023-33058
8.2 HIGH

Information disclosure in Modem while processing SIB5.

Feb 6, 2024
CVE-2023-33057
7.5 HIGH

Transient DOS in Multi-Mode Call Processor while processing UE policy container.

Feb 6, 2024
CVE-2023-33049
7.5 HIGH

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

Feb 6, 2024
CVE-2023-33046
7.8 HIGH

Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

Feb 6, 2024
CVE-2024-23304
7.5 HIGH

Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

Feb 6, 2024
CVE-2024-20816
8.0 HIGH

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20815
8.0 HIGH

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

Feb 6, 2024
CVE-2024-20813
8.4 HIGH

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-20812
8.4 HIGH

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Feb 6, 2024
CVE-2024-22773
8.1 HIGH

Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

Feb 6, 2024
CVE-2023-47889
7.8 HIGH

The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device …

Feb 6, 2024
CVE-2023-47353
8.8 HIGH

An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

Feb 6, 2024
CVE-2023-46360
8.8 HIGH

Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.

Feb 6, 2024
CVE-2023-47354
7.8 HIGH

An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted …

Feb 6, 2024
CVE-2024-1072
8.2 HIGH

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of …

Feb 5, 2024
CVE-2024-0869
8.8 HIGH

The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due …

Feb 5, 2024
CVE-2024-0761
8.1 HIGH

The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in …

Feb 5, 2024
CVE-2024-0428
7.1 HIGH

The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.