CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42509
6.6 MEDIUM

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository …

Mar 7, 2024
CVE-2024-2245
5.4 MEDIUM

Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be executed in the 'username' …

Mar 7, 2024
CVE-2024-2241
6.3 MEDIUM

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

Mar 7, 2024
CVE-2024-28230
6.5 MEDIUM

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

Mar 7, 2024
CVE-2024-28229
6.5 MEDIUM

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

Mar 7, 2024
CVE-2024-28228
5.3 MEDIUM

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

Mar 7, 2024
CVE-2024-22256
4.3 MEDIUM

VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the …

Mar 7, 2024
CVE-2024-1534
6.4 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 …

Mar 7, 2024
CVE-2024-2136
6.4 MEDIUM

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and …

Mar 7, 2024
CVE-2023-41015
5.5 MEDIUM

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.

Mar 7, 2024
CVE-2022-46091
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 7, 2024
CVE-2024-1506
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in …

Mar 7, 2024
CVE-2024-1419
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget …

Mar 7, 2024
CVE-2024-1720
4.7 MEDIUM

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 7, 2024
CVE-2024-1500
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and …

Mar 7, 2024
CVE-2024-1377
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all …

Mar 7, 2024
CVE-2024-1366
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all …

Mar 7, 2024
CVE-2024-28216
5.4 MEDIUM

nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of …

Mar 7, 2024
CVE-2024-1761
6.4 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 …

Mar 7, 2024
CVE-2024-1460
5.6 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-1443
4.4 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-24389
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 7, 2024
CVE-2022-46089
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 7, 2024
CVE-2024-1299
6.5 MEDIUM

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user …

Mar 7, 2024
CVE-2023-51281
5.4 MEDIUM

Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and …

Mar 7, 2024
CVE-2023-49987
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2023-49986
4.7 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2024-2236
5.9 MEDIUM

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead …

Mar 6, 2024
CVE-2024-28111
6.5 MEDIUM

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these …

Mar 6, 2024
CVE-2024-27915
6.8 MEDIUM

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of …

Mar 6, 2024
CVE-2024-27288
6.3 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to …

Mar 6, 2024
CVE-2024-27287
6.5 MEDIUM

ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file …

Mar 6, 2024
CVE-2024-24766
6.2 MEDIUM

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration …

Mar 6, 2024
CVE-2023-50167
5.4 MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Mar 6, 2024
CVE-2024-2215
6.1 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, …

Mar 6, 2024
CVE-2024-28174
5.8 MEDIUM

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Mar 6, 2024
CVE-2024-28173
4.3 MEDIUM

In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

Mar 6, 2024
CVE-2024-28162
4.2 MEDIUM

In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower …

Mar 6, 2024
CVE-2024-28161
5.3 MEDIUM

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled …

Mar 6, 2024
CVE-2024-28159
4.3 MEDIUM

A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

Mar 6, 2024
CVE-2024-28158
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.

Mar 6, 2024
CVE-2024-28156
5.4 MEDIUM

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28155
4.3 MEDIUM

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available …

Mar 6, 2024
CVE-2024-28154
6.5 MEDIUM

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Mar 6, 2024
CVE-2024-28153
5.4 MEDIUM

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Mar 6, 2024
CVE-2024-28152
6.3 MEDIUM

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" …

Mar 6, 2024
CVE-2024-28151
4.3 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with …

Mar 6, 2024
CVE-2024-28150
4.7 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, …

Mar 6, 2024
CVE-2024-28149
6.5 MEDIUM

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks …

Mar 6, 2024
CVE-2024-20346
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack …

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.