CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24130
6.1 MEDIUM

Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.

Feb 7, 2024
CVE-2023-39196
5.3 MEDIUM

Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The …

Feb 7, 2024
CVE-2024-1110
5.3 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in …

Feb 7, 2024
CVE-2024-1109
5.3 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() …

Feb 7, 2024
CVE-2024-1079
5.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all …

Feb 7, 2024
CVE-2024-1078
4.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions …

Feb 7, 2024
CVE-2024-0977
4.4 MEDIUM

The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image URLs in the …

Feb 7, 2024
CVE-2023-40355
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code …

Feb 7, 2024
CVE-2024-1055
5.4 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all …

Feb 7, 2024
CVE-2024-1037
6.1 MEDIUM

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up …

Feb 7, 2024
CVE-2024-0256
6.4 MEDIUM

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and …

Feb 7, 2024
CVE-2024-23447
5.3 MEDIUM

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write …

Feb 7, 2024
CVE-2024-23446
6.5 MEDIUM

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the …

Feb 7, 2024
CVE-2024-0849
5.0 MEDIUM

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

Feb 7, 2024
CVE-2023-6388
5.0 MEDIUM

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

Feb 7, 2024
CVE-2024-1268
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The …

Feb 7, 2024
CVE-2024-22021
4.3 MEDIUM

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one …

Feb 7, 2024
CVE-2024-1264
6.3 MEDIUM

A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the …

Feb 7, 2024
CVE-2024-0971
6.5 MEDIUM

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

Feb 7, 2024
CVE-2024-0955
4.8 MEDIUM

A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead …

Feb 7, 2024
CVE-2024-24255
4.2 MEDIUM

A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.

Feb 6, 2024
CVE-2024-22388
5.9 MEDIUM

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and …

Feb 6, 2024
CVE-2024-1263
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of …

Feb 6, 2024
CVE-2024-1262
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file …

Feb 6, 2024
CVE-2024-24254
4.2 MEDIUM

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and …

Feb 6, 2024
CVE-2024-1261
6.3 MEDIUM

A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api/controllers/merchant/app/ComboController.php of the …

Feb 6, 2024
CVE-2024-1260
6.3 MEDIUM

A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the …

Feb 6, 2024
CVE-2023-45227
5.4 MEDIUM

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

Feb 6, 2024
CVE-2023-45222
5.4 MEDIUM

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the …

Feb 6, 2024
CVE-2023-45213
6.6 MEDIUM

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-42765
5.4 MEDIUM

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP …

Feb 6, 2024
CVE-2023-40544
5.7 MEDIUM

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via …

Feb 6, 2024
CVE-2023-40143
5.4 MEDIUM

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload …

Feb 6, 2024
CVE-2024-1259
6.3 MEDIUM

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 6, 2024
CVE-2024-22241
4.3 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner …

Feb 6, 2024
CVE-2024-22240
4.9 MEDIUM

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to …

Feb 6, 2024
CVE-2024-22239
5.3 MEDIUM

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2024-22238
6.4 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user …

Feb 6, 2024
CVE-2024-1255
5.3 MEDIUM

A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The …

Feb 6, 2024
CVE-2024-1254
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the …

Feb 6, 2024
CVE-2024-22331
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy …

Feb 6, 2024
CVE-2024-1253
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is some …

Feb 6, 2024
CVE-2024-1252
5.5 MEDIUM

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file …

Feb 6, 2024
CVE-2024-24291
6.1 MEDIUM

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

Feb 6, 2024
CVE-2024-23344
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process …

Feb 6, 2024
CVE-2024-1251
5.5 MEDIUM

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The …

Feb 6, 2024
CVE-2023-46183
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force …

Feb 6, 2024
CVE-2024-0911
5.5 MEDIUM

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a …

Feb 6, 2024
CVE-2024-0690
5.0 MEDIUM

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in …

Feb 6, 2024
CVE-2024-24943
5.3 MEDIUM

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.