CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28091
6.1 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User Defined Service in managed_services_add.asp (the victim …

Mar 28, 2024
CVE-2024-28090
5.4 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User name in dyn_dns.asp.

Mar 28, 2024
CVE-2024-25506
6.5 MEDIUM

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

Mar 28, 2024
CVE-2024-31065
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.

Mar 28, 2024
CVE-2024-31064
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

Mar 28, 2024
CVE-2024-31063
6.4 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.

Mar 28, 2024
CVE-2024-31062
6.3 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

Mar 28, 2024
CVE-2024-31061
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field.

Mar 28, 2024
CVE-2024-27719
6.1 MEDIUM

A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to …

Mar 28, 2024
CVE-2024-25971
5.5 MEDIUM

Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2024-25963
5.9 MEDIUM

Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25954
5.3 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial …

Mar 28, 2024
CVE-2024-25953
6.0 MEDIUM

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25952
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25961
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2023-42956
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web …

Mar 28, 2024
CVE-2023-42936
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42930
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be …

Mar 28, 2024
CVE-2023-42896
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42893
5.5 MEDIUM

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS …

Mar 28, 2024
CVE-2023-40390
5.5 MEDIUM

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be …

Mar 28, 2024
CVE-2024-3042
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The …

Mar 28, 2024
CVE-2024-3041
6.3 MEDIUM

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. …

Mar 28, 2024
CVE-2024-3040
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. …

Mar 28, 2024
CVE-2024-3039
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the …

Mar 28, 2024
CVE-2024-31140
4.1 MEDIUM

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

Mar 28, 2024
CVE-2024-31139
5.9 MEDIUM

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

Mar 28, 2024
CVE-2024-31138
4.6 MEDIUM

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

Mar 28, 2024
CVE-2024-31137
6.8 MEDIUM

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

Mar 28, 2024
CVE-2024-31135
6.1 MEDIUM

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

Mar 28, 2024
CVE-2024-31134
6.5 MEDIUM

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

Mar 28, 2024
CVE-2024-30603
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30598
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30597
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30590
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30588
4.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30586
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30585
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-29898
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki …

Mar 28, 2024
CVE-2024-29897
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm …

Mar 28, 2024
CVE-2024-29200
6.8 MEDIUM

Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the …

Mar 28, 2024
CVE-2024-30594
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30422
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through …

Mar 28, 2024
CVE-2024-30421
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.

Mar 28, 2024
CVE-2024-2818
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 …

Mar 28, 2024
CVE-2024-29240
4.3 MEDIUM

Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via …

Mar 28, 2024
CVE-2024-29239
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29238
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-29237
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29236
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.