CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-34311
4.3 MEDIUM

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session …

Feb 12, 2024
CVE-2022-34309
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2022-38714
4.9 MEDIUM

IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: …

Feb 12, 2024
CVE-2022-34310
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2024-25360
5.3 MEDIUM

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

Feb 12, 2024
CVE-2024-0421
5.3 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an …

Feb 12, 2024
CVE-2024-0420
5.4 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing …

Feb 12, 2024
CVE-2024-0250
6.1 MEDIUM

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php …

Feb 12, 2024
CVE-2024-0248
4.3 MEDIUM

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as …

Feb 12, 2024
CVE-2023-7233
4.8 MEDIUM

The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6591
4.8 MEDIUM

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 12, 2024
CVE-2023-6501
4.3 MEDIUM

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Feb 12, 2024
CVE-2023-6499
5.4 MEDIUM

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 12, 2024
CVE-2023-6082
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6081
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6681
5.3 MEDIUM

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary …

Feb 12, 2024
CVE-2024-1062
5.5 MEDIUM

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in …

Feb 12, 2024
CVE-2024-1439
6.5 MEDIUM

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with …

Feb 12, 2024
CVE-2024-24935
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4.

Feb 12, 2024
CVE-2024-24929
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

Feb 12, 2024
CVE-2024-24887
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This …

Feb 12, 2024
CVE-2024-24884
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.

Feb 12, 2024
CVE-2024-24875
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

Feb 12, 2024
CVE-2023-46615
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

Feb 12, 2024
CVE-2023-41708
5.4 MEDIUM

References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script …

Feb 12, 2024
CVE-2023-41707
6.5 MEDIUM

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the …

Feb 12, 2024
CVE-2023-41706
6.5 MEDIUM

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App …

Feb 12, 2024
CVE-2023-41705
6.5 MEDIUM

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the …

Feb 12, 2024
CVE-2023-41703
6.1 MEDIUM

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a …

Feb 12, 2024
CVE-2024-24889
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All 404 Pages Redirect to Homepage allows Stored XSS.This issue …

Feb 12, 2024
CVE-2023-51403
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through …

Feb 12, 2024
CVE-2023-51370
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam WP Chat App allows Stored XSS.This issue affects WP Chat App: from …

Feb 12, 2024
CVE-2023-50875
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue …

Feb 12, 2024
CVE-2023-47526
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chart Builder Team Chartify – WordPress Chart Plugin allows Stored XSS.This issue affects …

Feb 12, 2024
CVE-2024-24931
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swadeshswain Before After Image Slider WP allows Stored XSS.This issue affects Before After …

Feb 12, 2024
CVE-2024-24930
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Buttons Shortcode and Widget allows Stored XSS.This issue affects Buttons Shortcode and …

Feb 12, 2024
CVE-2024-24928
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arunas Liuiza Content Cards allows Stored XSS.This issue affects Content Cards: from n/a …

Feb 12, 2024
CVE-2024-25741
5.5 MEDIUM

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or …

Feb 12, 2024
CVE-2024-25740
5.5 MEDIUM

A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.

Feb 12, 2024
CVE-2024-25739
5.5 MEDIUM

create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and crash, because of a missing check for ubi->leb_size.

Feb 12, 2024
CVE-2023-52429
5.5 MEDIUM

dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing …

Feb 12, 2024
CVE-2024-1151
5.5 MEDIUM

A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls …

Feb 11, 2024
CVE-2024-21875
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on risc-v (billboard modules) …

Feb 11, 2024
CVE-2024-25715
6.1 MEDIUM

Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.

Feb 11, 2024
CVE-2024-1432
5.0 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22 and classified as problematic. This issue affects the function apply_xseg of the …

Feb 11, 2024
CVE-2024-1431
4.3 MEDIUM

A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of …

Feb 11, 2024
CVE-2024-1430
4.3 MEDIUM

A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm …

Feb 11, 2024
CVE-2024-22313
6.2 MEDIUM

IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, …

Feb 10, 2024
CVE-2024-22312
4.4 MEDIUM

IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: …

Feb 10, 2024
CVE-2024-22361
5.9 MEDIUM

IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker …

Feb 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.