CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45234
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited …

Jan 16, 2024
CVE-2023-45233
7.5 HIGH

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can …

Jan 16, 2024
CVE-2023-45232
7.5 HIGH

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be …

Jan 16, 2024
CVE-2023-45230
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by …

Jan 16, 2024
CVE-2023-2655
7.2 HIGH

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2023-1405
7.5 HIGH

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is …

Jan 16, 2024
CVE-2022-3899
8.1 HIGH

The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing …

Jan 16, 2024
CVE-2022-3764
7.2 HIGH

The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

Jan 16, 2024
CVE-2022-3604
7.8 HIGH

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Jan 16, 2024
CVE-2022-1538
7.2 HIGH

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as …

Jan 16, 2024
CVE-2021-24869
8.8 HIGH

The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading …

Jan 16, 2024
CVE-2021-24566
8.8 HIGH

The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

Jan 16, 2024
CVE-2021-24151
7.2 HIGH

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via …

Jan 16, 2024
CVE-2024-0582
7.8 HIGH

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and …

Jan 16, 2024
CVE-2024-0575
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 16, 2024
CVE-2024-0574
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0573
8.8 HIGH

A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. …

Jan 16, 2024
CVE-2024-0572
8.8 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 16, 2024
CVE-2024-0571
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0570
7.3 HIGH

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. …

Jan 16, 2024
CVE-2024-0567
7.5 HIGH

A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a …

Jan 16, 2024
CVE-2024-0553
7.5 HIGH

A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 …

Jan 16, 2024
CVE-2024-0556
7.1 HIGH

A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and …

Jan 16, 2024
CVE-2023-52105
7.5 HIGH

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52104
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52102
7.5 HIGH

Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52100
7.5 HIGH

The Celia Keyboard module has a vulnerability in access control. Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52099
7.5 HIGH

Vulnerability of foreground service restrictions being bypassed in the NMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52116
7.5 HIGH

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 16, 2024
CVE-2023-52115
7.5 HIGH

The iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.

Jan 16, 2024
CVE-2023-52114
7.5 HIGH

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52108
7.5 HIGH

Vulnerability of process priorities being raised in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52107
7.5 HIGH

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-52098
7.5 HIGH

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52113
7.5 HIGH

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Jan 16, 2024
CVE-2023-52111
7.5 HIGH

Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

Jan 16, 2024
CVE-2023-52110
7.5 HIGH

The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

Jan 16, 2024
CVE-2023-52109
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-4566
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44117
7.5 HIGH

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Jan 16, 2024
CVE-2023-44112
7.5 HIGH

Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

Jan 16, 2024
CVE-2024-21674
7.5 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21673
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2024-21672
8.8 HIGH

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with …

Jan 16, 2024
CVE-2023-22526
8.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a …

Jan 16, 2024
CVE-2024-22428
7.0 HIGH

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and …

Jan 16, 2024
CVE-2024-22362
7.5 HIGH

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) …

Jan 16, 2024
CVE-2023-51282
7.5 HIGH

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

Jan 16, 2024
CVE-2023-51257
7.8 HIGH

An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.

Jan 16, 2024
CVE-2023-51059
8.8 HIGH

An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.