CVE Database

39445+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49550
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

Jan 2, 2024
CVE-2023-49549
7.5 HIGH

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.

Jan 2, 2024
CVE-2024-21632
8.6 HIGH

omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute …

Jan 2, 2024
CVE-2023-50020
7.5 HIGH

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Jan 2, 2024
CVE-2023-4164
8.4 HIGH

There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional …

Jan 2, 2024
CVE-2024-21627
8.1 HIGH

PrestaShop is an open-source e-commerce platform. Prior to versions 8.1.3 and 1.7.8.11, some event attributes are not detected by the `isCleanHTML` method. Some modules using …

Jan 2, 2024
CVE-2023-45893
7.5 HIGH

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive …

Jan 2, 2024
CVE-2023-45892
7.5 HIGH

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

Jan 2, 2024
CVE-2022-3010
7.5 HIGH

The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes it possible for an attacker to calculate …

Jan 2, 2024
CVE-2024-0193
7.8 HIGH

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, …

Jan 2, 2024
CVE-2023-47039
7.8 HIGH

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell …

Jan 2, 2024
CVE-2023-43514
8.4 HIGH

Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.

Jan 2, 2024
CVE-2023-43512
7.5 HIGH

Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual …

Jan 2, 2024
CVE-2023-43511
7.5 HIGH

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

Jan 2, 2024
CVE-2023-33120
7.8 HIGH

Memory corruption in Audio when memory map command is executed consecutively in ADSP.

Jan 2, 2024
CVE-2023-33118
7.8 HIGH

Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL.

Jan 2, 2024
CVE-2023-33117
7.8 HIGH

Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

Jan 2, 2024
CVE-2023-33116
7.5 HIGH

Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

Jan 2, 2024
CVE-2023-33114
8.4 HIGH

Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time.

Jan 2, 2024
CVE-2023-33113
8.4 HIGH

Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.

Jan 2, 2024
CVE-2023-33112
7.5 HIGH

Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.

Jan 2, 2024
CVE-2023-33110
7.8 HIGH

The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close …

Jan 2, 2024
CVE-2023-33109
7.5 HIGH

Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

Jan 2, 2024
CVE-2023-33108
8.4 HIGH

Memory corruption in Graphics Driver when destroying a context with KGSL_GPU_AUX_COMMAND_TIMELINE objects queued.

Jan 2, 2024
CVE-2023-33094
8.4 HIGH

Memory corruption while running VK synchronization with KASAN enabled.

Jan 2, 2024
CVE-2023-33085
7.8 HIGH

Memory corruption in wearables while processing data from AON.

Jan 2, 2024
CVE-2023-33062
7.5 HIGH

Transient DOS in WLAN Firmware while parsing a BTM request.

Jan 2, 2024
CVE-2023-33040
7.5 HIGH

Transient DOS in Data Modem during DTLS handshake.

Jan 2, 2024
CVE-2023-33037
7.1 HIGH

Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data.

Jan 2, 2024
CVE-2023-33036
7.1 HIGH

Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.

Jan 2, 2024
CVE-2023-33033
8.4 HIGH

Memory corruption in Audio during playback with speaker protection.

Jan 2, 2024
CVE-2023-33014
7.6 HIGH

Information disclosure in Core services while processing a Diag command.

Jan 2, 2024
CVE-2023-26159
7.3 HIGH

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When …

Jan 2, 2024
CVE-2023-32890
7.5 HIGH

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional …

Jan 2, 2024
CVE-2023-32889
7.5 HIGH

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2023-32888
7.5 HIGH

In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2023-32887
7.5 HIGH

In Modem IMS Stack, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with …

Jan 2, 2024
CVE-2023-32886
7.5 HIGH

In Modem IMS SMS UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial …

Jan 2, 2024
CVE-2024-0182
7.3 HIGH

A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jan 1, 2024
CVE-2023-50096
7.5 HIGH

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This …

Jan 1, 2024
CVE-2023-50094
8.8 HIGH

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The …

Jan 1, 2024
CVE-2023-6421
7.5 HIGH

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

Jan 1, 2024
CVE-2023-6271
7.5 HIGH

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak …

Jan 1, 2024
CVE-2023-6113
7.5 HIGH

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information …

Jan 1, 2024
CVE-2023-6064
7.5 HIGH

The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

Jan 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.