CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-44595
5.3 MEDIUM

Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.

Mar 21, 2024
CVE-2024-2464
6.3 MEDIUM

This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling …

Mar 21, 2024
CVE-2024-29244
5.3 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3g parameter at /apply.cgi.

Mar 21, 2024
CVE-2024-27995
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & …

Mar 21, 2024
CVE-2023-47715
4.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.16 could allow an authenticated user with read-only permissions to add or delete entries from an existing HyperVisor …

Mar 21, 2024
CVE-2024-2494
6.2 MEDIUM

A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays before the non-negative length check …

Mar 21, 2024
CVE-2024-29880
4.2 MEDIUM

In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain permissions of the user running the agent process

Mar 21, 2024
CVE-2024-28834
5.3 MEDIUM

A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. …

Mar 21, 2024
CVE-2024-26643
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout While the rhashtable …

Mar 21, 2024
CVE-2024-26642
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout …

Mar 21, 2024
CVE-2024-26307
5.3 MEDIUM

Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of someone renaming the file out from …

Mar 21, 2024
CVE-2024-29133
5.4 MEDIUM

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which …

Mar 21, 2024
CVE-2024-2754
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation …

Mar 21, 2024
CVE-2024-28835
5.0 MEDIUM

A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the …

Mar 21, 2024
CVE-2024-28635
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute arbitrary code and obtain sensitive information via the title …

Mar 21, 2024
CVE-2024-22724
6.6 MEDIUM

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

Mar 21, 2024
CVE-2023-48903
6.1 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in …

Mar 21, 2024
CVE-2024-2713
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file …

Mar 21, 2024
CVE-2024-2712
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. This issue affects some unknown processing of …

Mar 21, 2024
CVE-2024-2016
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the …

Mar 21, 2024
CVE-2024-2015
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation …

Mar 21, 2024
CVE-2024-2007
5.3 MEDIUM

A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component …

Mar 21, 2024
CVE-2024-28102
6.8 MEDIUM

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can cause a denial of service attack by passing in …

Mar 21, 2024
CVE-2024-27932
4.6 MEDIUM

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno improperly checks that an import specifier's hostname …

Mar 21, 2024
CVE-2024-27927
6.5 MEDIUM

RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to send …

Mar 21, 2024
CVE-2024-27926
6.1 MEDIUM

RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.d8ca915, ahen the specially crafted image is supplied to …

Mar 21, 2024
CVE-2024-27626
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.

Mar 21, 2024
CVE-2024-27291
6.1 MEDIUM

Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an …

Mar 21, 2024
CVE-2024-27290
6.1 MEDIUM

Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML into a field, including the field …

Mar 21, 2024
CVE-2024-27094
6.5 MEDIUM

OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 …

Mar 21, 2024
CVE-2024-26196
4.3 MEDIUM

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

Mar 21, 2024
CVE-2024-25811
6.5 MEDIUM

An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.

Mar 21, 2024
CVE-2024-25359
6.6 MEDIUM

An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.

Mar 21, 2024
CVE-2024-25167
6.1 MEDIUM

Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script to the argument description parameter when …

Mar 21, 2024
CVE-2024-24818
5.9 MEDIUM

EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to …

Mar 21, 2024
CVE-2024-24110
6.5 MEDIUM

SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.

Mar 21, 2024
CVE-2024-24028
5.9 MEDIUM

Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo.

Mar 21, 2024
CVE-2024-22352
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.

Mar 21, 2024
CVE-2024-1908
6.3 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to …

Mar 21, 2024
CVE-2024-1503
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Mar 21, 2024
CVE-2024-1502
5.4 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Mar 21, 2024
CVE-2024-1450
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.10 …

Mar 21, 2024
CVE-2024-1326
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 …

Mar 21, 2024
CVE-2024-1278
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 21, 2024
CVE-2024-1214
4.3 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1213
5.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1142
5.4 MEDIUM

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 …

Mar 21, 2024
CVE-2024-0966
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-6500
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-49985
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.