CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6326
5.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.10. This …

Mar 2, 2024
CVE-2024-0378
6.5 MEDIUM

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when …

Mar 2, 2024
CVE-2024-1775
5.4 MEDIUM

The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting via the ‘error_description’ parameter in all versions up …

Mar 2, 2024
CVE-2024-1592
4.3 MEDIUM

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is …

Mar 2, 2024
CVE-2024-25064
4.3 MEDIUM

Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter …

Mar 2, 2024
CVE-2024-25438
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Mar 1, 2024
CVE-2024-25436
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Mar 1, 2024
CVE-2024-25434
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Mar 1, 2024
CVE-2024-24512
6.1 MEDIUM

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.

Mar 1, 2024
CVE-2024-24511
6.1 MEDIUM

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.

Mar 1, 2024
CVE-2024-27744
6.1 MEDIUM

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter …

Mar 1, 2024
CVE-2024-27743
6.1 MEDIUM

Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter …

Mar 1, 2024
CVE-2023-49544
4.9 MEDIUM

A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the …

Mar 1, 2024
CVE-2023-49540
6.1 MEDIUM

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts …

Mar 1, 2024
CVE-2023-49539
6.1 MEDIUM

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts …

Mar 1, 2024
CVE-2021-47080
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prevent divide-by-zero error triggered by the user The user_entry_size is supplied by the user …

Mar 1, 2024
CVE-2021-47079
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: ideapad-laptop: fix a NULL pointer dereference The third parameter of dytc_cql_command should not be …

Mar 1, 2024
CVE-2021-47078
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Clear all QP fields if creation failed rxe_qp_do_cleanup() relies on valid pointer values in …

Mar 1, 2024
CVE-2021-47077
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Add pointer checks in qedf_update_link_speed() The following trace was observed: [ 14.042059] Call …

Mar 1, 2024
CVE-2021-47076
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Return CQE error if invalid lkey was supplied RXE is missing update of WQE …

Mar 1, 2024
CVE-2021-47075
5.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak in nvmet_alloc_ctrl() When creating ctrl in nvmet_alloc_ctrl(), if the cntlid_min is …

Mar 1, 2024
CVE-2021-47074
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-loop: fix memory leak in nvme_loop_create_ctrl() When creating loop ctrl in nvme_loop_create_ctrl(), if nvme_init_ctrl() fails, …

Mar 1, 2024
CVE-2021-47073
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios init_dell_smbios_wmi() only registers the dell_smbios_wmi_driver on systems where …

Mar 1, 2024
CVE-2021-47072
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix removed dentries still existing after log is synced When we move one inode …

Mar 1, 2024
CVE-2021-47071
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix a memory leak in error handling paths If 'vmbus_establish_gpadl()' fails, the (recv|send)_gpadl will …

Mar 1, 2024
CVE-2021-47070
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix another memory leak in error handling paths Memory allocated by 'vmbus_alloc_ring()' at the …

Mar 1, 2024
CVE-2024-23492
5.7 MEDIUM

A weak encoding is used to transmit credentials for WS203VICM.

Mar 1, 2024
CVE-2024-20328
5.3 MEDIUM

A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The …

Mar 1, 2024
CVE-2024-2077
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file index.php. The …

Mar 1, 2024
CVE-2024-2076
5.3 MEDIUM

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-2074
6.3 MEDIUM

A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation …

Mar 1, 2024
CVE-2024-2073
6.3 MEDIUM

A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Mar 1, 2024
CVE-2024-27734
6.1 MEDIUM

A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fields …

Mar 1, 2024
CVE-2024-27559
6.3 MEDIUM

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

Mar 1, 2024
CVE-2024-27558
6.1 MEDIUM

Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.

Mar 1, 2024
CVE-2023-52556
6.2 MEDIUM

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

Mar 1, 2024
CVE-2024-2069
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file /endpoint/delete-faq.php. The manipulation …

Mar 1, 2024
CVE-2024-27499
6.5 MEDIUM

Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

Mar 1, 2024
CVE-2024-27296
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped …

Mar 1, 2024
CVE-2024-27140
5.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from …

Mar 1, 2024
CVE-2024-2067
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. …

Mar 1, 2024
CVE-2024-0967
4.3 MEDIUM

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

Mar 1, 2024
CVE-2023-50378
6.1 MEDIUM

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited …

Mar 1, 2024
CVE-2024-2064
4.3 MEDIUM

A vulnerability has been found in rahman SelectCours 1.0 and classified as problematic. Affected by this vulnerability is the function getCacheNames of the file CacheController.java …

Mar 1, 2024
CVE-2024-27569
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27568
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27567
6.5 MEDIUM

LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause …

Mar 1, 2024
CVE-2023-52497
6.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, …

Mar 1, 2024
CVE-2023-46951
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

Mar 1, 2024
CVE-2023-46950
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.

Mar 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.