CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6247
6.5 MEDIUM

The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.

Feb 29, 2024
CVE-2023-51835
6.8 MEDIUM

An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.

Feb 29, 2024
CVE-2023-51775
6.5 MEDIUM

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50436
5.3 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version …

Feb 29, 2024
CVE-2023-49932
5.4 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.

Feb 29, 2024
CVE-2023-48653
4.3 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events …

Feb 29, 2024
CVE-2023-48651
4.3 MEDIUM

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

Feb 29, 2024
CVE-2023-48650
4.8 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.

Feb 29, 2024
CVE-2023-45874
4.3 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

Feb 29, 2024
CVE-2023-44347
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44346
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44345
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44344
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44343
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44342
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44341
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-43769
6.3 MEDIUM

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

Feb 29, 2024
CVE-2023-41165
4.8 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and …

Feb 29, 2024
CVE-2023-38372
5.9 MEDIUM

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM …

Feb 29, 2024
CVE-2023-37495
5.9 MEDIUM

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® …

Feb 29, 2024
CVE-2023-27151
6.1 MEDIUM

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity …

Feb 29, 2024
CVE-2023-25926
5.5 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Feb 29, 2024
CVE-2022-36677
6.1 MEDIUM

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

Feb 29, 2024
CVE-2024-26146
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a …

Feb 29, 2024
CVE-2024-26141
5.8 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with …

Feb 29, 2024
CVE-2024-25126
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, …

Feb 29, 2024
CVE-2024-26559
5.3 MEDIUM

An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.

Feb 28, 2024
CVE-2024-25579
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Feb 28, 2024
CVE-2024-22532
6.5 MEDIUM

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

Feb 28, 2024
CVE-2024-21798
4.8 MEDIUM

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another …

Feb 28, 2024
CVE-2023-5617
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error …

Feb 28, 2024
CVE-2024-26450
5.4 MEDIUM

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery …

Feb 28, 2024
CVE-2024-25868
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType …

Feb 28, 2024
CVE-2023-45873
6.5 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Feb 28, 2024
CVE-2023-25922
4.3 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 28, 2024
CVE-2024-27285
5.4 MEDIUM

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate …

Feb 28, 2024
CVE-2024-25435
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Feb 28, 2024
CVE-2024-25202
6.1 MEDIUM

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

Feb 28, 2024
CVE-2023-52048
4.7 MEDIUM

RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

Feb 28, 2024
CVE-2024-27948
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24.

Feb 28, 2024
CVE-2023-51692
4.3 MEDIUM

Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

Feb 28, 2024
CVE-2023-51533
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.

Feb 28, 2024
CVE-2024-27103
6.1 MEDIUM

Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, …

Feb 28, 2024
CVE-2024-21749
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.

Feb 28, 2024
CVE-2024-0560
6.3 MEDIUM

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy …

Feb 28, 2024
CVE-2023-52226
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

Feb 28, 2024
CVE-2023-52223
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.

Feb 28, 2024
CVE-2023-51683
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from …

Feb 28, 2024
CVE-2023-51681
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a …

Feb 28, 2024
CVE-2024-24705
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.