CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-43449
8.8 HIGH

An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

Jan 16, 2024
CVE-2023-51810
7.5 HIGH

SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the …

Jan 16, 2024
CVE-2023-47460
8.8 HIGH

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

Jan 16, 2024
CVE-2023-7206
7.8 HIGH

In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, …

Jan 15, 2024
CVE-2024-0562
7.8 HIGH

A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated …

Jan 15, 2024
CVE-2023-6991
8.8 HIGH

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow …

Jan 15, 2024
CVE-2023-6620
7.2 HIGH

The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a …

Jan 15, 2024
CVE-2023-6029
7.5 HIGH

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from …

Jan 15, 2024
CVE-2023-5905
8.1 HIGH

The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged …

Jan 15, 2024
CVE-2023-50729
8.4 HIGH

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers …

Jan 15, 2024
CVE-2023-4818
7.6 HIGH

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by …

Jan 15, 2024
CVE-2023-42137
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have …

Jan 15, 2024
CVE-2023-42136
7.8 HIGH

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with …

Jan 15, 2024
CVE-2024-0542
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. Affected by this issue is the function formWifiMacFilterGet of the component …

Jan 15, 2024
CVE-2024-0541
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component …

Jan 15, 2024
CVE-2024-0539
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456) and classified as critical. This issue affects the function formQosManage_user of the component httpd. The manipulation of …

Jan 15, 2024
CVE-2024-0538
8.8 HIGH

A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical. This vulnerability affects the function formQosManage_auto of the component httpd. The manipulation …

Jan 15, 2024
CVE-2024-0537
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda W9 1.0.0.7(4456). This affects the function setWrlBasicInfo of the component httpd. The manipulation of …

Jan 15, 2024
CVE-2024-0536
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda W9 1.0.0.7(4456). Affected by this issue is the function setWrlAccessList of the component …

Jan 15, 2024
CVE-2024-0535
8.8 HIGH

A vulnerability classified as critical was found in Tenda PA6 1.0.1.21. Affected by this vulnerability is the function cgiPortMapAdd of the file /portmap of the …

Jan 15, 2024
CVE-2024-0534
7.2 HIGH

A vulnerability classified as critical has been found in Tenda A15 15.13.07.13. Affected is an unknown function of the file /goform/SetOnlineDevName of the component Web-based …

Jan 15, 2024
CVE-2024-0533
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of …

Jan 15, 2024
CVE-2023-48383
7.5 HIGH

NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass …

Jan 15, 2024
CVE-2024-0532
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as critical. This vulnerability affects the function set_repeat5 of the file /goform/WifiExtraSet of …

Jan 15, 2024
CVE-2024-0531
7.2 HIGH

A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the …

Jan 15, 2024
CVE-2024-0510
7.3 HIGH

A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of …

Jan 13, 2024
CVE-2024-0480
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is the function index of the …

Jan 13, 2024
CVE-2024-0479
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of …

Jan 13, 2024
CVE-2023-52289
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI …

Jan 13, 2024
CVE-2023-52288
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI …

Jan 13, 2024
CVE-2023-51070
7.5 HIGH

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the …

Jan 13, 2024
CVE-2023-51066
8.8 HIGH

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

Jan 13, 2024
CVE-2023-51065
7.5 HIGH

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from …

Jan 13, 2024
CVE-2023-51063
8.8 HIGH

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component …

Jan 13, 2024
CVE-2023-51804
7.5 HIGH

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

Jan 13, 2024
CVE-2023-46942
7.5 HIGH

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

Jan 13, 2024
CVE-2023-33472
8.8 HIGH

An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain …

Jan 13, 2024
CVE-2024-22142
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from …

Jan 13, 2024
CVE-2024-0474
7.3 HIGH

A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Jan 12, 2024
CVE-2023-48166
7.5 HIGH

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents …

Jan 12, 2024
CVE-2023-49647
8.8 HIGH

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an …

Jan 12, 2024
CVE-2023-48297
8.6 HIGH

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to …

Jan 12, 2024
CVE-2023-42463
7.4 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow …

Jan 12, 2024
CVE-2023-31035
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at …

Jan 12, 2024
CVE-2023-31032
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability …

Jan 12, 2024
CVE-2023-46805
8.2 HIGH KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources …

Jan 12, 2024
CVE-2023-31036
7.5 HIGH

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an …

Jan 12, 2024
CVE-2023-51949
8.8 HIGH

Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller

Jan 12, 2024
CVE-2023-49261
7.5 HIGH

The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

Jan 12, 2024
CVE-2023-49259
7.5 HIGH

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.