CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0887
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the …

Jan 25, 2024
CVE-2024-22639
6.1 MEDIUM

iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.

Jan 25, 2024
CVE-2024-22637
6.1 MEDIUM

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

Jan 25, 2024
CVE-2024-22635
6.1 MEDIUM

WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.

Jan 25, 2024
CVE-2024-0885
5.3 MEDIUM

A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the component HTTP GET Request Handler. The manipulation …

Jan 25, 2024
CVE-2024-0884
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec …

Jan 25, 2024
CVE-2023-52046
4.8 MEDIUM

Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute …

Jan 25, 2024
CVE-2024-21630
4.3 MEDIUM

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links …

Jan 25, 2024
CVE-2023-41474
6.5 MEDIUM

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

Jan 25, 2024
CVE-2024-0883
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare …

Jan 25, 2024
CVE-2024-0882
4.3 MEDIUM

A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the …

Jan 25, 2024
CVE-2024-0880
4.3 MEDIUM

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/edit?id=2 of …

Jan 25, 2024
CVE-2024-0879
6.5 MEDIUM

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email …

Jan 25, 2024
CVE-2023-6282
5.4 MEDIUM

IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this …

Jan 25, 2024
CVE-2023-33760
5.3 MEDIUM

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via …

Jan 25, 2024
CVE-2023-33758
6.1 MEDIUM

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login …

Jan 25, 2024
CVE-2023-33757
5.9 MEDIUM

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before …

Jan 25, 2024
CVE-2024-23307
4.4 MEDIUM

Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow.

Jan 25, 2024
CVE-2024-22099
6.3 MEDIUM

NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program …

Jan 25, 2024
CVE-2024-0625
4.4 MEDIUM

The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 …

Jan 25, 2024
CVE-2024-0688
4.4 MEDIUM

The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.1.4 due …

Jan 25, 2024
CVE-2024-0624
5.3 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jan 25, 2024
CVE-2024-0617
5.3 MEDIUM

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in …

Jan 25, 2024
CVE-2024-23644
6.8 MEDIUM

Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 and `trillium-client` prior to 0.5.4, insufficient validation of …

Jan 24, 2024
CVE-2021-43584
4.8 MEDIUM

DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code …

Jan 24, 2024
CVE-2024-23905
5.4 MEDIUM

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for …

Jan 24, 2024
CVE-2024-23903
5.3 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, …

Jan 24, 2024
CVE-2024-23902
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

Jan 24, 2024
CVE-2024-23901
6.5 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share …

Jan 24, 2024
CVE-2024-23900
4.3 MEDIUM

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace …

Jan 24, 2024
CVE-2024-23899
6.5 MEDIUM

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file …

Jan 24, 2024
CVE-2024-22720
4.8 MEDIUM

Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.

Jan 24, 2024
CVE-2024-22725
6.1 MEDIUM

Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.

Jan 24, 2024
CVE-2023-44281
6.6 MEDIUM

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially …

Jan 24, 2024
CVE-2024-22141
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

Jan 24, 2024
CVE-2023-6697
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions …

Jan 24, 2024
CVE-2023-51702
6.5 MEDIUM

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as …

Jan 24, 2024
CVE-2023-50944
6.5 MEDIUM

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Jan 24, 2024
CVE-2024-22301
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On line: from n/a through …

Jan 24, 2024
CVE-2024-22294
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.

Jan 24, 2024
CVE-2024-22134
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through …

Jan 24, 2024
CVE-2024-0854
5.4 MEDIUM

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote …

Jan 24, 2024
CVE-2023-44001
5.4 MEDIUM

An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-44000
5.4 MEDIUM

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43999
5.4 MEDIUM

An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43998
5.4 MEDIUM

An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43997
5.4 MEDIUM

An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43996
5.4 MEDIUM

An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43995
5.4 MEDIUM

An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43994
5.4 MEDIUM

An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.