CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0664
4.4 MEDIUM

The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social Widget in all versions up to, …

Jan 27, 2024
CVE-2023-6497
4.4 MEDIUM

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to …

Jan 27, 2024
CVE-2023-6482
5.2 MEDIUM

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerprint sensor …

Jan 27, 2024
CVE-2023-52187
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Thomas Maier Image Source Control Lite – Show Image Credits and Captions.This issue affects Image …

Jan 27, 2024
CVE-2023-29081
5.5 MEDIUM

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause …

Jan 26, 2024
CVE-2024-0941
5.5 MEDIUM

A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the …

Jan 26, 2024
CVE-2024-0939
6.3 MEDIUM

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the …

Jan 26, 2024
CVE-2024-20305
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against …

Jan 26, 2024
CVE-2024-20263
5.8 MEDIUM

A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series …

Jan 26, 2024
CVE-2024-0938
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file /general/email/inbox/delete_webmail.php. …

Jan 26, 2024
CVE-2024-0937
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in van_der_Schaar LAB synthcity 0.2.9. Affected by this issue is the function load_from_file of the …

Jan 26, 2024
CVE-2024-23820
5.3 MEDIUM

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on the model …

Jan 26, 2024
CVE-2024-0936
6.3 MEDIUM

A vulnerability classified as critical was found in van_der_Schaar LAB TemporAI 0.0.3. Affected by this vulnerability is the function load_from_file of the component PKL File …

Jan 26, 2024
CVE-2024-0933
6.3 MEDIUM

A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model\Upload.php. The …

Jan 26, 2024
CVE-2024-0932
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This issue affects the function setSmartPowerManagement. The manipulation of the argument …

Jan 26, 2024
CVE-2024-0931
4.7 MEDIUM

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. This vulnerability affects the function saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to …

Jan 26, 2024
CVE-2024-0930
4.7 MEDIUM

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function fromSetWirelessRepeat. The manipulation of the argument wpapsk_crypto leads to …

Jan 26, 2024
CVE-2024-0929
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of …

Jan 26, 2024
CVE-2024-0928
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been declared as critical. Affected by this vulnerability is the function fromDhcpListClient. The manipulation of …

Jan 26, 2024
CVE-2024-22551
6.1 MEDIUM

WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.

Jan 26, 2024
CVE-2024-22550
6.1 MEDIUM

An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

Jan 26, 2024
CVE-2024-0927
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page …

Jan 26, 2024
CVE-2024-0926
4.7 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This issue affects the function formWifiWpsOOB. The manipulation of the argument index leads …

Jan 26, 2024
CVE-2024-0925
4.7 MEDIUM

A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list …

Jan 26, 2024
CVE-2024-0924
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49_multi_TDE01. This affects the function formSetPPTPServer. The manipulation of the argument startIp leads …

Jan 26, 2024
CVE-2024-0923
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this issue is the function formSetDeviceName. The manipulation of …

Jan 26, 2024
CVE-2024-0922
4.7 MEDIUM

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49_multi_TDE01. Affected by this vulnerability is the function formQuickIndex. The manipulation of the argument PPPOEPassword …

Jan 26, 2024
CVE-2024-0921
4.7 MEDIUM

A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 26, 2024
CVE-2024-0727
5.5 MEDIUM

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading …

Jan 26, 2024
CVE-2023-48129
5.4 MEDIUM

An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2024-23388
6.1 MEDIUM

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a …

Jan 26, 2024
CVE-2023-48135
5.4 MEDIUM

An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48133
5.4 MEDIUM

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48132
5.4 MEDIUM

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48131
5.4 MEDIUM

An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48130
5.4 MEDIUM

An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48128
5.4 MEDIUM

An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48127
5.4 MEDIUM

An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-48126
5.4 MEDIUM

An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 26, 2024
CVE-2023-6159
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 …

Jan 26, 2024
CVE-2023-5612
5.3 MEDIUM

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to …

Jan 26, 2024
CVE-2024-21387
5.3 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21382
4.3 MEDIUM

Microsoft Edge for Android Information Disclosure Vulnerability

Jan 26, 2024
CVE-2024-0456
4.3 MEDIUM

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able …

Jan 26, 2024
CVE-2023-5933
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions after 13.7 before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. Improper …

Jan 26, 2024
CVE-2024-21619
5.3 MEDIUM

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS …

Jan 25, 2024
CVE-2024-0890
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation …

Jan 25, 2024
CVE-2024-0889
5.3 MEDIUM

A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command …

Jan 25, 2024
CVE-2024-23055
6.1 MEDIUM

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

Jan 25, 2024
CVE-2024-0888
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. …

Jan 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.