CVE Database

39445+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32366
7.8 HIGH

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and …

Jan 10, 2024
CVE-2022-47965
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-47915
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2022-46721
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code …

Jan 10, 2024
CVE-2023-51127
7.5 HIGH

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, …

Jan 10, 2024
CVE-2023-29445
7.8 HIGH

An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM.

Jan 10, 2024
CVE-2023-50916
7.2 HIGH

Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. …

Jan 10, 2024
CVE-2023-46712
7.2 HIGH

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically …

Jan 10, 2024
CVE-2023-44250
8.8 HIGH

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy HA cluster version …

Jan 10, 2024
CVE-2023-49810
7.3 HIGH

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-49738
7.5 HIGH

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary …

Jan 10, 2024
CVE-2023-49589
8.8 HIGH

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead …

Jan 10, 2024
CVE-2023-48730
8.5 HIGH

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can …

Jan 10, 2024
CVE-2023-45139
7.5 HIGH

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker …

Jan 10, 2024
CVE-2023-41056
8.1 HIGH

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to …

Jan 10, 2024
CVE-2023-48266
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48265
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48264
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48263
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48262
8.1 HIGH

The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Jan 10, 2024
CVE-2023-48257
7.8 HIGH

The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on …

Jan 10, 2024
CVE-2023-48253
8.8 HIGH

The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this …

Jan 10, 2024
CVE-2023-48252
8.8 HIGH

The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

Jan 10, 2024
CVE-2023-48251
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

Jan 10, 2024
CVE-2023-48250
8.1 HIGH

The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

Jan 10, 2024
CVE-2023-48243
8.1 HIGH

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) …

Jan 10, 2024
CVE-2023-49471
8.8 HIGH

Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which …

Jan 10, 2024
CVE-2023-49427
7.5 HIGH

Buffer Overflow vulnerability in Tenda AX12 V22.03.01.46, allows remote attackers to cause a denial of service (DoS) via list parameter in SetNetControlList function.

Jan 10, 2024
CVE-2023-48864
7.5 HIGH

SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.

Jan 10, 2024
CVE-2024-21643
7.1 HIGH

IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol …

Jan 10, 2024
CVE-2024-0359
7.3 HIGH

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jan 10, 2024
CVE-2024-0352
7.3 HIGH

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component …

Jan 9, 2024
CVE-2023-47994
8.8 HIGH

An integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive information, cause a denial of service and/or run …

Jan 9, 2024
CVE-2023-47992
8.8 HIGH

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

Jan 9, 2024
CVE-2023-37297
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37296
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37295
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-37294
8.3 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of …

Jan 9, 2024
CVE-2023-34333
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-34332
7.8 HIGH

AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation …

Jan 9, 2024
CVE-2023-7032
7.8 HIGH

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by …

Jan 9, 2024
CVE-2024-21325
7.8 HIGH

Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21318
8.8 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-21312
7.5 HIGH

.NET Framework Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-21310
7.8 HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21309
7.8 HIGH

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-21307
7.5 HIGH

Remote Desktop Client Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20700
7.5 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-20698
7.8 HIGH

Windows Kernel Elevation of Privilege Vulnerability

Jan 9, 2024
CVE-2024-20697
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.