CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1198
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the …

Feb 3, 2024
CVE-2024-1196
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component …

Feb 2, 2024
CVE-2024-1195
5.5 MEDIUM

A vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library ITopVpnCallbackProcess.sys …

Feb 2, 2024
CVE-2024-1189
5.3 MEDIUM

A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Encryption Passphrase …

Feb 2, 2024
CVE-2023-37527
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code …

Feb 2, 2024
CVE-2024-23635
6.1 MEDIUM

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation …

Feb 2, 2024
CVE-2024-24160
5.4 MEDIUM

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

Feb 2, 2024
CVE-2024-23824
4.7 MEDIUM

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload …

Feb 2, 2024
CVE-2023-47567
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47566
6.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47561
5.5 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via …

Feb 2, 2024
CVE-2023-45028
5.5 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch …

Feb 2, 2024
CVE-2023-45027
5.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the …

Feb 2, 2024
CVE-2023-45026
5.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the …

Feb 2, 2024
CVE-2023-41283
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-41282
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-41281
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-41280
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41279
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41278
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41277
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41276
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41275
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41274
5.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch …

Feb 2, 2024
CVE-2023-41273
5.5 MEDIUM

A heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-39303
5.3 MEDIUM

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security …

Feb 2, 2024
CVE-2023-39302
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-32967
5.0 MEDIUM

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Feb 2, 2024
CVE-2021-21575
5.9 MEDIUM

Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

Feb 2, 2024
CVE-2023-6673
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-6672
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-47148
5.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured …

Feb 2, 2024
CVE-2023-47144
6.1 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Feb 2, 2024
CVE-2024-0963
6.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, …

Feb 2, 2024
CVE-2024-0844
4.7 MEDIUM

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. …

Feb 2, 2024
CVE-2024-24388
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

Feb 2, 2024
CVE-2023-51820
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

Feb 2, 2024
CVE-2023-51072
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious …

Feb 2, 2024
CVE-2021-22281
6.3 MEDIUM

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Feb 2, 2024
CVE-2024-21863
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2024-0285
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2023-45734
4.2 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

Feb 2, 2024
CVE-2024-1162
4.3 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due …

Feb 2, 2024
CVE-2024-1047
5.3 MEDIUM

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 2, 2024
CVE-2024-21485
6.5 MEDIUM

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package …

Feb 2, 2024
CVE-2024-1073
6.4 MEDIUM

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due …

Feb 2, 2024
CVE-2024-0685
5.9 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via …

Feb 2, 2024
CVE-2023-38263
6.5 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-38020
4.3 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

Feb 2, 2024
CVE-2022-40744
4.8 MEDIUM

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.