CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26475
5.5 MEDIUM

An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent …

Mar 14, 2024
CVE-2024-2256
6.4 MEDIUM

The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact_button and bw_button shortcodes in all versions up …

Mar 14, 2024
CVE-2024-27265
4.5 MEDIUM

IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …

Mar 14, 2024
CVE-2024-24770
5.3 MEDIUM

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it …

Mar 14, 2024
CVE-2024-24562
5.4 MEDIUM

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been …

Mar 14, 2024
CVE-2024-23823
4.2 MEDIUM

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has …

Mar 14, 2024
CVE-2024-28849
6.5 MEDIUM

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header …

Mar 14, 2024
CVE-2023-43490
5.3 MEDIUM

Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure …

Mar 14, 2024
CVE-2023-39368
6.5 MEDIUM

Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.

Mar 14, 2024
CVE-2023-38575
5.5 MEDIUM

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Mar 14, 2024
CVE-2023-35191
6.8 MEDIUM

Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via network access.

Mar 14, 2024
CVE-2023-32633
6.7 MEDIUM

Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local …

Mar 14, 2024
CVE-2023-28746
6.5 MEDIUM

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable …

Mar 14, 2024
CVE-2023-28389
6.7 MEDIUM

Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local …

Mar 14, 2024
CVE-2023-22655
6.1 MEDIUM

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to …

Mar 14, 2024
CVE-2024-28323
6.5 MEDIUM

The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The …

Mar 14, 2024
CVE-2024-25156
6.5 MEDIUM

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web …

Mar 14, 2024
CVE-2024-28418
6.5 MEDIUM

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

Mar 14, 2024
CVE-2024-28417
6.3 MEDIUM

Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

Mar 14, 2024
CVE-2024-27986
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor Addons by Livemesh allows Stored XSS.This issue affects Elementor Addons by …

Mar 14, 2024
CVE-2024-0313
5.5 MEDIUM

A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately …

Mar 14, 2024
CVE-2024-0312
5.5 MEDIUM

A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

Mar 14, 2024
CVE-2024-0311
5.5 MEDIUM

A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

Mar 14, 2024
CVE-2024-22398
4.9 MEDIUM

An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative …

Mar 14, 2024
CVE-2024-22396
5.3 MEDIUM

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially …

Mar 14, 2024
CVE-2024-1884
6.5 MEDIUM

This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make …

Mar 14, 2024
CVE-2024-1883
6.3 MEDIUM

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL …

Mar 14, 2024
CVE-2024-25653
4.3 MEDIUM

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system …

Mar 14, 2024
CVE-2024-25651
5.3 MEDIUM

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user …

Mar 14, 2024
CVE-2024-25649
6.7 MEDIUM

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data …

Mar 14, 2024
CVE-2024-1223
4.8 MEDIUM

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid …

Mar 14, 2024
CVE-2024-25650
5.9 MEDIUM

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to …

Mar 14, 2024
CVE-2024-28251
5.6 MEDIUM

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. …

Mar 14, 2024
CVE-2024-2242
6.1 MEDIUM

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 …

Mar 13, 2024
CVE-2024-2079
6.4 MEDIUM

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up …

Mar 13, 2024
CVE-2024-27703
5.4 MEDIUM

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

Mar 13, 2024
CVE-2023-38536
6.4 MEDIUM

HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.

Mar 13, 2024
CVE-2023-38535
4.7 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.

Mar 13, 2024
CVE-2024-28662
5.4 MEDIUM

A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.

Mar 13, 2024
CVE-2024-28193
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the settings, which can …

Mar 13, 2024
CVE-2024-28192
5.3 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public access token processing logic. …

Mar 13, 2024
CVE-2024-27097
4.3 MEDIUM

A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting …

Mar 13, 2024
CVE-2023-50726
6.4 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily override an …

Mar 13, 2024
CVE-2023-36238
6.5 MEDIUM

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

Mar 13, 2024
CVE-2024-24692
5.3 MEDIUM

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service …

Mar 13, 2024
CVE-2024-2433
4.3 MEDIUM

An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill …

Mar 13, 2024
CVE-2024-2432
4.5 MEDIUM

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. …

Mar 13, 2024
CVE-2024-2431
5.5 MEDIUM

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a user to …

Mar 13, 2024
CVE-2024-2418
6.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 13, 2024
CVE-2024-2403
5.9 MEDIUM

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.