CVE Database

39445+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-39336
8.8 HIGH

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to …

Jan 9, 2024
CVE-2023-27098
7.5 HIGH

TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

Jan 9, 2024
CVE-2024-21735
7.3 HIGH

SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This …

Jan 9, 2024
CVE-2024-21651
7.5 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to …

Jan 9, 2024
CVE-2024-21648
8.0 HIGH

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, …

Jan 9, 2024
CVE-2023-50162
7.2 HIGH

SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.

Jan 9, 2024
CVE-2023-52074
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.

Jan 8, 2024
CVE-2023-52073
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.

Jan 8, 2024
CVE-2023-52072
8.8 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.

Jan 8, 2024
CVE-2023-7218
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N350RT 9.3.5u.6139_B202012. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2023-52201
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brian D. Goad pTypeConverter.This issue affects pTypeConverter: from n/a through 0.2.8.1.

Jan 8, 2024
CVE-2023-52196
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Ewels CPT Bootstrap Carousel allows Reflected XSS.This issue affects CPT Bootstrap Carousel: …

Jan 8, 2024
CVE-2023-52142
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events …

Jan 8, 2024
CVE-2023-49961
7.5 HIGH

WALLIX Bastion 7.x, 8.x, 9.x and 10.x and WALLIX Access Manager 3.x and 4.x have Incorrect Access Control which can lead to sensitive data exposure.

Jan 8, 2024
CVE-2023-52213
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows …

Jan 8, 2024
CVE-2023-52206
7.7 HIGH

Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.

Jan 8, 2024
CVE-2023-52204
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Javik Randomize.This issue affects Randomize: from n/a through 1.4.3.

Jan 8, 2024
CVE-2023-47890
8.8 HIGH

pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.

Jan 8, 2024
CVE-2023-6845
8.8 HIGH

The CommentTweets WordPress plugin through 0.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted …

Jan 8, 2024
CVE-2023-6750
7.5 HIGH

The Clone WordPress plugin before 2.4.3 uses buffer files to store in-progress backup informations, which is stored at a publicly accessible, statically defined file path.

Jan 8, 2024
CVE-2023-6631
7.8 HIGH

PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted …

Jan 8, 2024
CVE-2023-6532
8.8 HIGH

The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 8, 2024
CVE-2023-6528
8.8 HIGH

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially …

Jan 8, 2024
CVE-2023-6505
7.5 HIGH

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

Jan 8, 2024
CVE-2023-6383
7.5 HIGH

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization …

Jan 8, 2024
CVE-2023-6140
8.8 HIGH

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP …

Jan 8, 2024
CVE-2023-6042
7.5 HIGH

Any unauthenticated user may send e-mail from the site with any title or content to the admin

Jan 8, 2024
CVE-2023-5957
7.2 HIGH

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged …

Jan 8, 2024
CVE-2023-5235
8.8 HIGH

The Ovic Responsive WPBakery WordPress plugin before 1.2.9 does not limit which options can be updated via some of its AJAX actions, which may allow …

Jan 8, 2024
CVE-2023-52190
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Swings Coupon Referral Program.This issue affects Coupon Referral Program: from n/a through 1.7.2.

Jan 8, 2024
CVE-2021-3600
7.8 HIGH

It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and …

Jan 8, 2024
CVE-2022-3328
7.8 HIGH

Race condition in snap-confine's must_mkdir_and_open_with_perms()

Jan 8, 2024
CVE-2024-21747
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP | Complete HR solution with recruitment & job …

Jan 8, 2024
CVE-2023-39444
7.8 HIGH

Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim …

Jan 8, 2024
CVE-2023-39443
7.8 HIGH

Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim …

Jan 8, 2024
CVE-2023-39414
7.0 HIGH

Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. …

Jan 8, 2024
CVE-2023-39413
7.0 HIGH

Multiple integer underflow vulnerabilities exist in the LXT2 lxt2_rd_iter_radix shift operation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. …

Jan 8, 2024
CVE-2023-39317
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A …

Jan 8, 2024
CVE-2023-39316
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 num_dict_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A …

Jan 8, 2024
CVE-2023-39275
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39274
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39273
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39272
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39271
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39270
7.8 HIGH

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39235
7.8 HIGH

Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-39234
7.8 HIGH

Multiple out-of-bounds write vulnerabilities exist in the VZT vzt_rd_process_block autosort functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-38657
7.8 HIGH

An out-of-bounds write vulnerability exists in the LXT2 zlib block decompression functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-38653
7.0 HIGH

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. …

Jan 8, 2024
CVE-2023-38652
7.0 HIGH

Multiple integer overflow vulnerabilities exist in the VZT vzt_rd_block_vch_decode dict parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to memory corruption. …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.