CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-44308
6.1 MEDIUM

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to …

Feb 20, 2024
CVE-2023-5190
6.1 MEDIUM

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 …

Feb 20, 2024
CVE-2022-45320
6.3 MEDIUM

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users …

Feb 20, 2024
CVE-2024-1559
6.5 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due …

Feb 20, 2024
CVE-2024-1510
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up …

Feb 20, 2024
CVE-2024-21890
6.5 MEDIUM

The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For …

Feb 20, 2024
CVE-2023-6399
5.7 MEDIUM

A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 …

Feb 20, 2024
CVE-2023-6397
6.5 MEDIUM

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 …

Feb 20, 2024
CVE-2024-26129
5.8 MEDIUM

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. …

Feb 19, 2024
CVE-2024-25640
4.6 MEDIUM

Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in …

Feb 19, 2024
CVE-2024-25982
4.3 MEDIUM

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Feb 19, 2024
CVE-2024-25981
4.3 MEDIUM

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided …

Feb 19, 2024
CVE-2024-25980
4.3 MEDIUM

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional …

Feb 19, 2024
CVE-2024-25979
5.3 MEDIUM

The URL parameters accepted by forum search were not limited to the allowed parameters.

Feb 19, 2024
CVE-2024-1346
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used …

Feb 19, 2024
CVE-2024-1345
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the …

Feb 19, 2024
CVE-2024-1344
6.8 MEDIUM

Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of …

Feb 19, 2024
CVE-2024-1343
4.7 MEDIUM

A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in …

Feb 19, 2024
CVE-2024-1580
5.9 MEDIUM

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the …

Feb 19, 2024
CVE-2024-26308
5.5 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to …

Feb 19, 2024
CVE-2024-26328
6.0 MEDIUM

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

Feb 19, 2024
CVE-2024-26327
5.3 MEDIUM

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to …

Feb 19, 2024
CVE-2024-26318
6.1 MEDIUM

Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.

Feb 19, 2024
CVE-2020-36774
5.5 MEDIUM

plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

Feb 19, 2024
CVE-2023-5779
4.4 MEDIUM

can: out of bounds in remove_rx_filter function

Feb 18, 2024
CVE-2023-52380
4.3 MEDIUM

Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52368
5.3 MEDIUM

Input verification vulnerability in the account module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52365
5.3 MEDIUM

Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52363
5.3 MEDIUM

Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by …

Feb 18, 2024
CVE-2023-52358
6.2 MEDIUM

Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2024-22337
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2024-22336
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2024-22335
5.1 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in log files that could be …

Feb 17, 2024
CVE-2023-50951
4.0 MEDIUM

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 in some circumstances will log some sensitive information about invalid …

Feb 17, 2024
CVE-2024-25297
4.8 MEDIUM

Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

Feb 17, 2024
CVE-2024-21500
4.8 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the …

Feb 17, 2024
CVE-2024-21499
4.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability …

Feb 17, 2024
CVE-2024-21498
5.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with …

Feb 17, 2024
CVE-2024-21497
5.4 MEDIUM

Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into …

Feb 17, 2024
CVE-2024-21496
6.1 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to improper input sanitization. Although the Referer header …

Feb 17, 2024
CVE-2024-21495
6.5 MEDIUM

Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be …

Feb 17, 2024
CVE-2024-21494
5.4 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can …

Feb 17, 2024
CVE-2024-21493
5.3 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library …

Feb 17, 2024
CVE-2024-21492
4.8 MEDIUM

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the "Sign Out" button. User …

Feb 17, 2024
CVE-2024-20986
6.1 MEDIUM

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20984
4.4 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions that are affected are 8.0.35 and prior and …

Feb 17, 2024
CVE-2024-20982
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20980
5.4 MEDIUM

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability …

Feb 17, 2024
CVE-2024-20978
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024
CVE-2024-20976
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. …

Feb 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.