CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22771
7.4 HIGH

Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22770
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22769
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-22768
7.4 HIGH

Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Jan 23, 2024
CVE-2024-23222
8.8 HIGH KEV

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS …

Jan 23, 2024
CVE-2024-23214
8.8 HIGH

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

Jan 23, 2024
CVE-2024-23213
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

Jan 23, 2024
CVE-2024-23212
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey …

Jan 23, 2024
CVE-2024-23209
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.

Jan 23, 2024
CVE-2024-23208
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. …

Jan 23, 2024
CVE-2024-23204
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey …

Jan 23, 2024
CVE-2024-23203
7.5 HIGH

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma …

Jan 23, 2024
CVE-2023-42881
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing a file may lead to unexpected app termination …

Jan 23, 2024
CVE-2024-23345
7.1 HIGH

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or …

Jan 23, 2024
CVE-2024-23342
7.4 HIGH

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve …

Jan 23, 2024
CVE-2024-23678
7.5 HIGH

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization …

Jan 22, 2024
CVE-2023-24135
7.8 HIGH

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary …

Jan 22, 2024
CVE-2023-7082
7.2 HIGH

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly …

Jan 22, 2024
CVE-2024-0605
7.5 HIGH

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, …

Jan 22, 2024
CVE-2022-45792
7.8 HIGH

Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with …

Jan 22, 2024
CVE-2022-45790
8.6 HIGH

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary …

Jan 22, 2024
CVE-2024-0778
8.0 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this …

Jan 22, 2024
CVE-2024-22895
8.8 HIGH

DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

Jan 22, 2024
CVE-2020-36771
7.8 HIGH

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication …

Jan 22, 2024
CVE-2024-22233
7.5 HIGH

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) …

Jan 22, 2024
CVE-2023-52354
7.5 HIGH

chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.

Jan 22, 2024
CVE-2024-21484
7.5 HIGH

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts …

Jan 22, 2024
CVE-2023-47352
8.8 HIGH

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

Jan 22, 2024
CVE-2024-23768
8.8 HIGH

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can …

Jan 22, 2024
CVE-2024-23750
8.8 HIGH

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

Jan 22, 2024
CVE-2024-23744
7.5 HIGH

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Jan 21, 2024
CVE-2023-52353
7.5 HIGH

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated …

Jan 21, 2024
CVE-2024-23732
7.5 HIGH

The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.

Jan 21, 2024
CVE-2023-6531
7.0 HIGH

A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() …

Jan 21, 2024
CVE-2024-23726
8.8 HIGH

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) …

Jan 21, 2024
CVE-2024-0521
7.8 HIGH

Code Injection in paddlepaddle/paddle

Jan 20, 2024
CVE-2023-7063
7.2 HIGH

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due …

Jan 20, 2024
CVE-2023-47024
8.8 HIGH

Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed …

Jan 20, 2024
CVE-2023-51926
7.5 HIGH

YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.

Jan 20, 2024
CVE-2024-0739
7.3 HIGH

A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The …

Jan 19, 2024
CVE-2024-23689
8.8 HIGH

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate …

Jan 19, 2024
CVE-2024-23684
7.5 HIGH

Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause …

Jan 19, 2024
CVE-2024-23683
8.2 HIGH

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker …

Jan 19, 2024
CVE-2024-23682
8.2 HIGH

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. …

Jan 19, 2024
CVE-2024-23681
8.2 HIGH

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker …

Jan 19, 2024
CVE-2024-22421
7.6 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious …

Jan 19, 2024
CVE-2023-49329
7.2 HIGH

Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This arises from improper handling of …

Jan 19, 2024
CVE-2024-23331
7.5 HIGH

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of …

Jan 19, 2024
CVE-2023-6043
7.8 HIGH

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated …

Jan 19, 2024
CVE-2023-50447
8.1 HIGH

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.