CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-7248
5.0 MEDIUM

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by …

Mar 15, 2024
CVE-2024-28851
4.0 MEDIUM

The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of …

Mar 15, 2024
CVE-2023-51699
4.0 MEDIUM

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can …

Mar 15, 2024
CVE-2024-2537
4.4 MEDIUM

Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

Mar 15, 2024
CVE-2024-2193
5.7 MEDIUM

A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can …

Mar 15, 2024
CVE-2024-2497
4.7 MEDIUM

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component …

Mar 15, 2024
CVE-2024-28401
5.4 MEDIUM

TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Control under the Wireless Page.

Mar 15, 2024
CVE-2023-7004
6.5 MEDIUM

The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device …

Mar 15, 2024
CVE-2023-7003
6.8 MEDIUM

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused …

Mar 15, 2024
CVE-2024-28403
5.4 MEDIUM

TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page.

Mar 15, 2024
CVE-2023-47699
6.1 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mar 15, 2024
CVE-2023-47147
5.9 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.

Mar 15, 2024
CVE-2023-46181
4.0 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM …

Mar 15, 2024
CVE-2021-38938
6.2 MEDIUM

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by …

Mar 15, 2024
CVE-2024-28319
6.2 MEDIUM

gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period media_tools/dash_client.c:6374

Mar 15, 2024
CVE-2023-51522
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Paid Member Subscriptions.This issue affects Paid Member Subscriptions: from n/a through 2.10.4.

Mar 15, 2024
CVE-2023-51369
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SysBasics Customize My Account for WooCommerce.This issue affects Customize My Account for WooCommerce: from n/a through 1.8.3.

Mar 15, 2024
CVE-2023-50898
5.4 MEDIUM

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

Mar 15, 2024
CVE-2023-50886
4.3 MEDIUM

Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.

Mar 15, 2024
CVE-2023-47162
6.1 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mar 15, 2024
CVE-2023-46182
5.4 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Mar 15, 2024
CVE-2023-46179
4.3 MEDIUM

IBM Sterling Secure Proxy 6.0.3 and 6.1.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …

Mar 15, 2024
CVE-2024-25596
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Doofinder Doofinder for WooCommerce allows Stored XSS.This issue affects Doofinder for WooCommerce: from …

Mar 15, 2024
CVE-2024-25593
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows Stored XSS.This issue affects NEX-Forms – …

Mar 15, 2024
CVE-2024-25592
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Broken Link Checker allows Stored XSS.This issue affects Broken Link Checker: …

Mar 15, 2024
CVE-2023-51525
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Veribo, Roland Murg WP Simple Booking Calendar.This issue affects WP Simple Booking Calendar: from n/a through 2.0.8.4.

Mar 15, 2024
CVE-2023-50861
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).This issue affects HUSKY – Products Filter for WooCommerce (formerly WOOF): …

Mar 15, 2024
CVE-2024-2495
5.2 MEDIUM

Cryptographic key vulnerability encoded in the FriendlyWrt firmware affecting version 2022-11-16.51b3d35. This vulnerability could allow an attacker to compromise the confidentiality and integrity of encrypted …

Mar 15, 2024
CVE-2024-27189
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchsquare WP Social Widget allows Stored XSS.This issue affects WP Social Widget: from …

Mar 15, 2024
CVE-2024-25936
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoundCloud Inc., Lawrie Malen SoundCloud Shortcode allows Stored XSS.This issue affects SoundCloud Shortcode: …

Mar 15, 2024
CVE-2024-25934
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.

Mar 15, 2024
CVE-2024-25919
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template allows Stored XSS.This issue affects Custom Field Template: …

Mar 15, 2024
CVE-2024-25916
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from …

Mar 15, 2024
CVE-2024-25598
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Elementor allows Stored XSS.This issue affects Livemesh Addons for …

Mar 15, 2024
CVE-2023-6725
5.5 MEDIUM

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A …

Mar 15, 2024
CVE-2024-23944
5.3 MEDIUM

Information disclosure in persistent watchers handling in Apache ZooKeeper due to missing ACL check. It allows an attacker to monitor child znodes by attaching a …

Mar 15, 2024
CVE-2024-2446
4.3 MEDIUM

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, …

Mar 15, 2024
CVE-2024-2445
6.1 MEDIUM

Mattermost Jira plugin versions shipped with Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to escape user-controlled …

Mar 15, 2024
CVE-2024-2483
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Surya2Developer Hostel Management Service 1.0. This issue affects some unknown processing of the file …

Mar 15, 2024
CVE-2024-2399
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, …

Mar 15, 2024
CVE-2024-1796
6.4 MEDIUM

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions …

Mar 15, 2024
CVE-2024-2481
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The …

Mar 15, 2024
CVE-2024-2480
6.3 MEDIUM

A vulnerability classified as critical was found in MHA Sistemas arMHAzena 9.6.0.0. This vulnerability affects unknown code of the component Executa Page. The manipulation of …

Mar 15, 2024
CVE-2024-2478
6.3 MEDIUM

A vulnerability was found in BradWenqiang HR 2.0. It has been rated as critical. Affected by this issue is the function selectAll of the file …

Mar 15, 2024
CVE-2024-2204
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 and 0x80002010 IOCTL codes of the zam64.sys and zamguard64.sys …

Mar 15, 2024
CVE-2024-2180
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers

Mar 15, 2024
CVE-2024-26454
5.4 MEDIUM

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

Mar 15, 2024
CVE-2024-26163
4.7 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 14, 2024
CVE-2024-1853
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.

Mar 14, 2024
CVE-2024-2249
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all …

Mar 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.