VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,759 CVE recordsPage 1069 of 1184 · EPSS data 2026.08.06
ReviewCritical
CVE-2023-39806

icms

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-39805

icms

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-33469

via_connect2, via_go2

In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-33468

via_connect2, via_go2

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-39004

opnsense

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-39003

opnsense

OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2023-38180

Microsoft .NET Core and Visual Studio

CVE-2023-38180 affects Microsoft .NET Core and Visual Studio. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2023-37646

file opener

An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-37687

online nurse hiring system

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-36095

langchain

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-38952

biotime

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-38951

biotime

ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2023-38950

biotime

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2023-38949

biotime

An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily reset the Administrator password via a crafted web request.

The CVSS severity warrants an early asset and exposure review.