CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20345
6.5 MEDIUM

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected …

Mar 6, 2024
CVE-2024-20336
6.5 MEDIUM

A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20335
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20301
6.2 MEDIUM

A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected …

Mar 6, 2024
CVE-2024-20292
4.4 MEDIUM

A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information …

Mar 6, 2024
CVE-2023-50740
5.3 MEDIUM

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend …

Mar 6, 2024
CVE-2024-25103
6.3 MEDIUM

This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with local administrative privileges could exploit this by …

Mar 6, 2024
CVE-2024-2211
4.6 MEDIUM

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu …

Mar 6, 2024
CVE-2024-26627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock for waking up EH handler Inside scsi_eh_wakeup(), …

Mar 6, 2024
CVE-2024-26626
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel …

Mar 6, 2024
CVE-2024-26623
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq There are multiple paths that can result in …

Mar 6, 2024
CVE-2023-52607
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which …

Mar 6, 2024
CVE-2023-52606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a …

Mar 6, 2024
CVE-2023-52597
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix setting of fpc register kvm_arch_vcpu_ioctl_set_fpu() allows to set the floating point control …

Mar 6, 2024
CVE-2023-52596
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix out of bounds access for empty sysctl registers When registering tables to the …

Mar 6, 2024
CVE-2023-52595
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: restart beacon queue when hardware reset When a hardware reset is triggered, all …

Mar 6, 2024
CVE-2023-52593
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' …

Mar 6, 2024
CVE-2023-52590
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be …

Mar 6, 2024
CVE-2023-52589
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ disable race issue In rkisp1_isp_stop() and rkisp1_csi_disable() the driver masks the …

Mar 6, 2024
CVE-2023-52587
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/ipoib: Fix mcast list locking Releasing the `priv->lock` while iterating the `priv->multicast_list` in `ipoib_mcast_join_task()` opens …

Mar 6, 2024
CVE-2023-52585
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper() Return invalid error code -EINVAL for invalid block …

Mar 6, 2024
CVE-2023-52583
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: fix deadlock or deadcode of misusing dget() The lock order is incorrect between denty …

Mar 6, 2024
CVE-2024-1989
6.4 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions …

Mar 6, 2024
CVE-2024-1771
4.3 MEDIUM

The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions …

Mar 6, 2024
CVE-2024-1760
4.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 6, 2024
CVE-2023-49977
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49976
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49974
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49973
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49971
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2024-27278
5.4 MEDIUM

OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which uses the affected product, when a user configures the profile …

Mar 6, 2024
CVE-2024-24785
5.4 MEDIUM

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing …

Mar 5, 2024
CVE-2024-24783
5.9 MEDIUM

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and …

Mar 5, 2024
CVE-2023-48644
6.1 MEDIUM

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance …

Mar 5, 2024
CVE-2023-45290
6.5 MEDIUM

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form …

Mar 5, 2024
CVE-2023-45289
4.3 MEDIUM

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not …

Mar 5, 2024
CVE-2024-1901
4.3 MEDIUM

Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make …

Mar 5, 2024
CVE-2024-1900
5.5 MEDIUM

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay …

Mar 5, 2024
CVE-2024-1898
4.3 MEDIUM

Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an …

Mar 5, 2024
CVE-2024-25615
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in …

Mar 5, 2024
CVE-2024-25614
5.5 MEDIUM

There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary …

Mar 5, 2024
CVE-2023-26282
4.2 MEDIUM

IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or …

Mar 5, 2024
CVE-2023-25681
5.3 MEDIUM

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and …

Mar 5, 2024
CVE-2022-22399
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Mar 5, 2024
CVE-2024-27931
5.8 MEDIUM

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside …

Mar 5, 2024
CVE-2024-27564
5.8 MEDIUM

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from …

Mar 5, 2024
CVE-2024-27563
5.3 MEDIUM

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2022-46088
6.1 MEDIUM

Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

Mar 5, 2024
CVE-2024-27627
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the …

Mar 5, 2024
CVE-2024-27625
4.8 MEDIUM

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, …

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.