CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22135
8.0 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Export & Order Import for …

Jan 24, 2024
CVE-2023-51711
7.8 HIGH

An issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitrary code every …

Jan 24, 2024
CVE-2023-43317
8.8 HIGH

An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage component.

Jan 24, 2024
CVE-2023-31037
7.2 HIGH

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. …

Jan 24, 2024
CVE-2024-0813
8.8 HIGH

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to …

Jan 24, 2024
CVE-2024-0812
8.8 HIGH

Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Jan 24, 2024
CVE-2024-0807
8.8 HIGH

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Jan 24, 2024
CVE-2024-0806
8.8 HIGH

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium …

Jan 24, 2024
CVE-2024-0804
7.5 HIGH

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML …

Jan 24, 2024
CVE-2023-47115
7.1 HIGH

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited …

Jan 23, 2024
CVE-2023-52338
7.8 HIGH

A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a …

Jan 23, 2024
CVE-2023-52337
7.8 HIGH

An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a …

Jan 23, 2024
CVE-2023-52331
7.1 HIGH

A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please …

Jan 23, 2024
CVE-2023-52325
7.5 HIGH

A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. …

Jan 23, 2024
CVE-2023-52324
8.8 HIGH

An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although …

Jan 23, 2024
CVE-2023-52094
7.8 HIGH

An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary …

Jan 23, 2024
CVE-2023-52093
7.8 HIGH

An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-52092
7.8 HIGH

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-52091
7.8 HIGH

An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-52090
7.8 HIGH

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an …

Jan 23, 2024
CVE-2023-47202
7.8 HIGH

A local file inclusion vulnerability on the Trend Micro Apex One management server could allow a local attacker to escalate privileges on affected installations. Please …

Jan 23, 2024
CVE-2023-47201
7.8 HIGH

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. …

Jan 23, 2024
CVE-2023-47200
7.8 HIGH

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. …

Jan 23, 2024
CVE-2023-47199
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47198
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47197
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47196
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47195
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47194
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47193
7.8 HIGH

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-47192
7.8 HIGH

An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: …

Jan 23, 2024
CVE-2023-46892
8.8 HIGH

The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication …

Jan 23, 2024
CVE-2023-7238
7.1 HIGH

A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the …

Jan 23, 2024
CVE-2023-6926
8.4 HIGH

There is an OS command injection vulnerability in Crestron AM-300 firmware version 1.4499.00018 which may enable a user of a limited-access SSH session to escalate …

Jan 23, 2024
CVE-2023-50275
7.5 HIGH

HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

Jan 23, 2024
CVE-2023-50274
7.8 HIGH

HPE OneView may allow command injection with local privilege escalation.

Jan 23, 2024
CVE-2024-0755
8.8 HIGH

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume …

Jan 23, 2024
CVE-2024-0751
8.8 HIGH

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Jan 23, 2024
CVE-2024-0750
8.8 HIGH

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects …

Jan 23, 2024
CVE-2024-0745
8.8 HIGH

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < …

Jan 23, 2024
CVE-2024-0744
7.5 HIGH

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox …

Jan 23, 2024
CVE-2024-0743
7.5 HIGH

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, …

Jan 23, 2024
CVE-2024-22705
7.8 HIGH

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between …

Jan 23, 2024
CVE-2023-51043
7.0 HIGH

In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.

Jan 23, 2024
CVE-2023-51042
7.8 HIGH

In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.

Jan 23, 2024
CVE-2024-23348
8.8 HIGH

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23182
8.1 HIGH

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23180
8.8 HIGH

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, …

Jan 23, 2024
CVE-2024-23842
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22772
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.