CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22136
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder.This issue affects Droit Elementor Addons – Widgets, …

Jan 31, 2024
CVE-2023-6780
5.3 MEDIUM

An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue …

Jan 31, 2024
CVE-2023-5992
5.6 MEDIUM

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak …

Jan 31, 2024
CVE-2024-22304
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through 2.3.2.

Jan 31, 2024
CVE-2024-22291
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.

Jan 31, 2024
CVE-2024-22285
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3.

Jan 31, 2024
CVE-2024-22143
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.

Jan 31, 2024
CVE-2024-0589
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to …

Jan 31, 2024
CVE-2024-1098
4.3 MEDIUM

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation …

Jan 31, 2024
CVE-2023-50357
5.4 MEDIUM

A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.

Jan 31, 2024
CVE-2023-50356
6.5 MEDIUM

SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a …

Jan 31, 2024
CVE-2023-44312
5.8 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Center before 2.1.0 (include). Users are recommended to upgrade …

Jan 31, 2024
CVE-2024-23170
5.5 MEDIUM

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This …

Jan 31, 2024
CVE-2024-1012
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The …

Jan 31, 2024
CVE-2024-0836
4.3 MEDIUM

The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jan 31, 2024
CVE-2024-0914
5.9 MEDIUM

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA …

Jan 31, 2024
CVE-2023-2439
6.4 MEDIUM

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient …

Jan 31, 2024
CVE-2024-22569
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

Jan 31, 2024
CVE-2024-23834
6.3 MEDIUM

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances …

Jan 30, 2024
CVE-2024-24567
4.8 MEDIUM

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call …

Jan 30, 2024
CVE-2024-21388
6.5 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 30, 2024
CVE-2024-24565
5.7 MEDIUM

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM …

Jan 30, 2024
CVE-2024-23840
5.5 MEDIUM

GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log …

Jan 30, 2024
CVE-2024-23647
6.5 MEDIUM

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE …

Jan 30, 2024
CVE-2023-46231
6.8 MEDIUM

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder …

Jan 30, 2024
CVE-2024-21653
6.5 MEDIUM

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh …

Jan 30, 2024
CVE-2023-37518
6.4 MEDIUM

HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running …

Jan 30, 2024
CVE-2024-0564
5.3 MEDIUM

A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version …

Jan 30, 2024
CVE-2024-1033
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is the function agent of the …

Jan 30, 2024
CVE-2024-0676
5.6 MEDIUM

Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine …

Jan 30, 2024
CVE-2024-0675
6.3 MEDIUM

Vulnerability of improper checking for unusual or exceptional conditions in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, the exploitation of which could allow …

Jan 30, 2024
CVE-2024-0674
6.3 MEDIUM

Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying …

Jan 30, 2024
CVE-2024-22894
6.8 MEDIUM

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or …

Jan 30, 2024
CVE-2024-1063
5.3 MEDIUM

Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.

Jan 30, 2024
CVE-2023-6374
5.9 MEDIUM

Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers allows a remote unauthenticated attacker to bypass authentication by …

Jan 30, 2024
CVE-2023-36259
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

Jan 30, 2024
CVE-2023-7225
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and height parameters in all versions up to, …

Jan 30, 2024
CVE-2024-22648
5.3 MEDIUM

A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan …

Jan 30, 2024
CVE-2024-22647
5.3 MEDIUM

An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an …

Jan 30, 2024
CVE-2024-22646
5.3 MEDIUM

An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist …

Jan 30, 2024
CVE-2024-22643
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.

Jan 30, 2024
CVE-2024-1027
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the component Post …

Jan 30, 2024
CVE-2023-51813
6.5 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter …

Jan 30, 2024
CVE-2023-37571
6.1 MEDIUM

Softing TH SCOPE through 3.70 allows XSS.

Jan 30, 2024
CVE-2024-23829
6.5 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, …

Jan 29, 2024
CVE-2024-23334
5.9 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary …

Jan 29, 2024
CVE-2024-1021
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the …

Jan 29, 2024
CVE-2023-4554
4.9 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor …

Jan 29, 2024
CVE-2023-4553
5.3 MEDIUM

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects …

Jan 29, 2024
CVE-2023-4552
5.5 MEDIUM

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.