CVE Database

39445+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-35960
7.8 HIGH

Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A …

Jan 8, 2024
CVE-2023-35959
7.8 HIGH

Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A …

Jan 8, 2024
CVE-2023-35958
7.8 HIGH

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-35957
7.8 HIGH

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-35956
7.8 HIGH

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-35955
7.8 HIGH

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. …

Jan 8, 2024
CVE-2023-35704
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-35703
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-35702
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-35128
7.0 HIGH

An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A …

Jan 8, 2024
CVE-2023-35057
7.8 HIGH

An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory …

Jan 8, 2024
CVE-2023-35004
7.8 HIGH

An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code …

Jan 8, 2024
CVE-2023-34436
7.8 HIGH

An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A …

Jan 8, 2024
CVE-2023-34087
7.8 HIGH

An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to …

Jan 8, 2024
CVE-2023-32650
7.0 HIGH

An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file …

Jan 8, 2024
CVE-2024-21644
7.5 HIGH

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask …

Jan 8, 2024
CVE-2023-7224
7.8 HIGH

OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable

Jan 8, 2024
CVE-2024-0307
7.3 HIGH

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Jan 8, 2024
CVE-2024-0306
7.3 HIGH

A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of …

Jan 8, 2024
CVE-2023-29051
8.1 HIGH

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the …

Jan 8, 2024
CVE-2023-29050
7.6 HIGH

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended …

Jan 8, 2024
CVE-2023-29048
8.8 HIGH

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and …

Jan 8, 2024
CVE-2024-0299
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. Affected by this vulnerability is the function setTracerouteCfg of the file …

Jan 8, 2024
CVE-2024-0298
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. Affected is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0297
7.3 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0296
7.3 HIGH

A vulnerability has been found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. This vulnerability affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 8, 2024
CVE-2024-0295
7.3 HIGH

A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. This affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 8, 2024
CVE-2024-0294
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file …

Jan 8, 2024
CVE-2023-47145
8.4 HIGH

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user …

Jan 7, 2024
CVE-2023-7210
7.3 HIGH

A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of …

Jan 7, 2024
CVE-2023-7209
7.5 HIGH

A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2024-0268
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown …

Jan 7, 2024
CVE-2023-7208
8.0 HIGH

A vulnerability classified as critical was found in Totolink X2000R_V2 2.0.0-B20230727.10434. This vulnerability affects the function formTmultiAP of the file /bin/boa. The manipulation leads to …

Jan 7, 2024
CVE-2024-0267
7.3 HIGH

A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the …

Jan 7, 2024
CVE-2024-0264
7.3 HIGH

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. …

Jan 7, 2024
CVE-2023-51441
7.2 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This …

Jan 6, 2024
CVE-2023-50612
7.8 HIGH

Insecure Permissions vulnerability in fit2cloud Cloud Explorer Lite version 1.4.1, allow local attackers to escalate privileges and obtain sensitive information via the cloud accounts parameter.

Jan 6, 2024
CVE-2024-21642
7.5 HIGH

D-Tale is a visualizer for Pandas data structures. Users hosting versions D-Tale prior to 3.9.0 publicly can be vulnerable to server-side request forgery (SSRF), allowing …

Jan 5, 2024
CVE-2024-0247
7.3 HIGH

A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the …

Jan 5, 2024
CVE-2023-47560
7.4 HIGH

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. …

Jan 5, 2024
CVE-2023-41288
8.8 HIGH

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. …

Jan 5, 2024
CVE-2023-39296
7.5 HIGH

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes …

Jan 5, 2024
CVE-2023-34326
7.8 HIGH

The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfunction (see stale DMA mappings) if …

Jan 5, 2024
CVE-2023-34325
7.8 HIGH

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains parsing code for several filesystems, most …

Jan 5, 2024
CVE-2023-34322
7.8 HIGH

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen …

Jan 5, 2024
CVE-2023-52143
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.

Jan 5, 2024
CVE-2023-50991
7.5 HIGH

Buffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoS) via the pingIp …

Jan 5, 2024
CVE-2023-52150
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.

Jan 5, 2024
CVE-2023-51502
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.

Jan 5, 2024
CVE-2024-22050
7.5 HIGH

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via …

Jan 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.