🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
Search: Time Range:
Sources: Clear All Filters
378,232+
CVEs Tracked
378,232
Exploit Intel
358,051
EPSS Scored
5,202
CISA KEV
2,698
Metasploit Modules
30,385
ExploitDB Entries
61
MITRE ATT&CK Maps
0
Actively Exploited
0
CISA KEV
2
PoC Available
0
Zero-Days
0
Recent Discoveries
0
Most Mentioned

CVE Severity Distribution (Last 30 Days)

Found 9 CVEs in the last 30 days.

CVE-2023-30799 CRITICAL CVSS: 9.1 EPSS: 1.4% VulnCheck KEV PoC Available CWE-269 T1068
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Published: 2023-07-19
CVE-2023-3079 HIGH CVSS: 8.8 EPSS: 32.1% VulnCheck KEV PoC Available CWE-843 CWE-843
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2023-06-05
CVE-2023-30795 HIGH CVSS: 7.8 EPSS: 0.2% CWE-125 CWE-125 T1005
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < V34.0.253), Parasolid V34.1 (All versions < V34.1.243), Parasolid V35.0 (All versions < V35.0.177), Parasolid V35.1 (All versions < V35.1.073). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process.
Published: 2023-08-08
CVE-2023-30796 HIGH CVSS: 7.8 EPSS: 0.2% CWE-125 CWE-125 T1005
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process.
Published: 2023-08-08
CVE-2023-30797 HIGH CVSS: 7.5 EPSS: 0.8% CWE-330 CWE-330 CWE-330
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
Published: 2023-04-19
CVE-2023-30798 HIGH CVSS: 7.5 EPSS: 1.3% CWE-400 CWE-400 T1499
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
Published: 2023-04-21
CVE-2023-30791 HIGH CVSS: 7.1 EPSS: 0.5% CWE-434 CWE-434 T1105
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
Published: 2023-07-15
CVE-2023-30792 MEDIUM CVSS: 6.1 EPSS: 0.4% CWE-79 CWE-79 T1189
Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
Published: 2023-04-29
CVE-2023-30790 MEDIUM CVSS: 5.4 EPSS: 0.6% CWE-79 CWE-79 T1189
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
Published: 2023-05-08