VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,676 CVE recordsPage 1071 of 1179 · EPSS data 2026.08.06
ReviewHigh
CVE-2023-31741

e2000 firmware, e2000

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-31740

e2000 firmware, e2000

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-31742

wrt54gl firmware, wrt54gl

There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-31729

a3300r firmware, a3300r

CVE-2023-31729 affects a3300r firmware, a3300r. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2023-27823

1080pstx

An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2022-47879

jedox, jedox cloud

A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-29863

weblab

Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-2610

vim vim/vim, vim

CVE-2023-2610 affects vim vim/vim, vim. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-30056

origination manager decision

A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.

The CVSS severity warrants an early asset and exposure review.
CISA KEVHigh
CVE-2023-29336

Microsoft Win32k

CVE-2023-29336 affects Microsoft Win32k. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
CISA KEVHigh
CVE-2023-24955

Microsoft SharePoint Server

CVE-2023-24955 affects Microsoft SharePoint Server. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2023-30237

cyberghost

CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2021-44283

shieldstore

A buffer overflow in the component /Enclave.cpp of Electronics and Telecommunications Research Institute ShieldStore commit 58d455617f99705f0ffd8a27616abdf77bdc1bdc allows attackers to cause an information leak via a crafted structure from an untrusted operating system.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2023-30185

crmeb

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2023-30243

application security gateway

Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.

The CVSS severity warrants an early asset and exposure review.