CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52486
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm: Don't unref the same fb many times by mistake due to deadlock handling If …

Mar 11, 2024
CVE-2024-0047
5.5 MEDIUM

In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local …

Mar 11, 2024
CVE-2024-0045
6.5 MEDIUM

In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure …

Mar 11, 2024
CVE-2024-0044
6.7 MEDIUM

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with …

Mar 11, 2024
CVE-2024-1441
5.5 MEDIUM

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This …

Mar 11, 2024
CVE-2024-28823
6.1 MEDIUM

Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html.

Mar 11, 2024
CVE-2024-2363
5.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. This vulnerability affects unknown code …

Mar 10, 2024
CVE-2024-2354
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of …

Mar 10, 2024
CVE-2024-2352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the …

Mar 10, 2024
CVE-2024-2351
6.3 MEDIUM

A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of …

Mar 9, 2024
CVE-2024-2333
6.3 MEDIUM

A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation …

Mar 9, 2024
CVE-2024-2332
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Mar 9, 2024
CVE-2024-2331
6.3 MEDIUM

A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file …

Mar 9, 2024
CVE-2024-1870
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in …

Mar 9, 2024
CVE-2024-2330
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Mar 9, 2024
CVE-2024-2329
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 9, 2024
CVE-2024-28089
5.2 MEDIUM

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel) to conduct a DOM-based stored …

Mar 9, 2024
CVE-2024-1767
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to …

Mar 9, 2024
CVE-2024-1320
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up …

Mar 9, 2024
CVE-2024-1125
5.4 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-1124
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the …

Mar 9, 2024
CVE-2024-1123
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-28180
4.3 MEDIUM

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed …

Mar 9, 2024
CVE-2024-28176
4.9 MEDIUM

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), …

Mar 9, 2024
CVE-2024-28122
6.8 MEDIUM

JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause …

Mar 9, 2024
CVE-2024-28753
6.5 MEDIUM

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.

Mar 9, 2024
CVE-2023-32264
5.8 MEDIUM

CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.

Mar 8, 2024
CVE-2022-43855
6.2 MEDIUM

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity …

Mar 8, 2024
CVE-2024-21901
4.7 MEDIUM

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. …

Mar 8, 2024
CVE-2024-21900
4.3 MEDIUM

An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via …

Mar 8, 2024
CVE-2023-47221
5.5 MEDIUM

A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected …

Mar 8, 2024
CVE-2023-34980
5.9 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Mar 8, 2024
CVE-2023-32969
4.9 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious …

Mar 8, 2024
CVE-2024-2319
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality …

Mar 8, 2024
CVE-2024-2318
4.3 MEDIUM

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of …

Mar 8, 2024
CVE-2024-2316
4.3 MEDIUM

A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnerability affects unknown code of the file /billing/bill/edit/ …

Mar 8, 2024
CVE-2024-2298
4.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in …

Mar 8, 2024
CVE-2024-1851
6.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in …

Mar 8, 2024
CVE-2024-27612
6.2 MEDIUM

Numbas editor before 7.3 mishandles editing of themes and extensions.

Mar 8, 2024
CVE-2024-1987
6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 …

Mar 8, 2024
CVE-2024-2283
6.3 MEDIUM

A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the …

Mar 8, 2024
CVE-2024-2281
6.3 MEDIUM

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the …

Mar 8, 2024
CVE-2024-2277
4.3 MEDIUM

A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Mar 8, 2024
CVE-2024-26309
5.3 MEDIUM

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via …

Mar 8, 2024
CVE-2024-25848
5.9 MEDIUM

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

Mar 8, 2024
CVE-2024-23297
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may …

Mar 8, 2024
CVE-2024-23295
5.5 MEDIUM

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able …

Mar 8, 2024
CVE-2024-23293
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23290
5.5 MEDIUM

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23287
5.5 MEDIUM

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS …

Mar 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.