CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0202
5.9 MEDIUM

A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS …

Feb 5, 2024
CVE-2023-27318
6.5 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash …

Feb 5, 2024
CVE-2024-22202
5.7 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to …

Feb 5, 2024
CVE-2024-24396
6.1 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2023-6028
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a …

Feb 5, 2024
CVE-2024-0953
6.1 MEDIUM

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified …

Feb 5, 2024
CVE-2024-24397
5.4 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2024-24768
6.5 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure …

Feb 5, 2024
CVE-2023-7216
5.3 MEDIUM

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a …

Feb 5, 2024
CVE-2024-24864
5.3 MEDIUM

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to …

Feb 5, 2024
CVE-2024-24860
4.6 MEDIUM

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24859
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial …

Feb 5, 2024
CVE-2024-24858
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading …

Feb 5, 2024
CVE-2024-24857
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to …

Feb 5, 2024
CVE-2024-24855
5.0 MEDIUM

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-23196
5.3 MEDIUM

A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-22386
5.3 MEDIUM

A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24865
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: …

Feb 5, 2024
CVE-2024-24841
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer …

Feb 5, 2024
CVE-2024-24839
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects …

Feb 5, 2024
CVE-2024-24838
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five …

Feb 5, 2024
CVE-2024-24870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a …

Feb 5, 2024
CVE-2024-20016
4.4 MEDIUM

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System …

Feb 5, 2024
CVE-2024-20013
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20012
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20010
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20006
6.7 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20002
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20001
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2023-5800
5.4 MEDIUM

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for …

Feb 5, 2024
CVE-2023-5677
6.3 MEDIUM

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation …

Feb 5, 2024
CVE-2023-51504
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's …

Feb 5, 2024
CVE-2021-46903
6.5 MEDIUM

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in …

Feb 4, 2024
CVE-2023-52426
5.5 MEDIUM

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

Feb 4, 2024
CVE-2018-25098
4.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in blockmason credit-protocol. It has been declared as problematic. Affected by this vulnerability is the function …

Feb 4, 2024
CVE-2023-6240
6.5 MEDIUM

A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt …

Feb 4, 2024
CVE-2019-25159
5.5 MEDIUM

A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This affects an unknown part of the …

Feb 4, 2024
CVE-2023-50947
5.4 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Feb 4, 2024
CVE-2023-33851
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: …

Feb 4, 2024
CVE-2024-0853
5.3 MEDIUM

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to …

Feb 3, 2024
CVE-2023-49950
5.4 MEDIUM

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template …

Feb 3, 2024
CVE-2024-23550
6.2 MEDIUM

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

Feb 3, 2024
CVE-2024-0909
5.3 MEDIUM

The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient …

Feb 3, 2024
CVE-2024-0895
5.4 MEDIUM

The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and …

Feb 3, 2024
CVE-2023-37528
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during …

Feb 3, 2024
CVE-2024-1200
5.3 MEDIUM

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation …

Feb 3, 2024
CVE-2023-32329
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-31006
6.5 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to …

Feb 3, 2024
CVE-2023-31005
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2024-1199
5.4 MEDIUM

A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.