CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0717
5.3 MEDIUM

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, …

Jan 19, 2024
CVE-2024-0714
6.3 MEDIUM

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 19, 2024
CVE-2022-47160
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register …

Jan 19, 2024
CVE-2022-45845
4.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Jan 19, 2024
CVE-2022-45083
6.6 MEDIUM

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This …

Jan 19, 2024
CVE-2024-22877
5.4 MEDIUM

StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious …

Jan 19, 2024
CVE-2024-22876
5.4 MEDIUM

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker …

Jan 19, 2024
CVE-2023-51946
6.1 MEDIUM

Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.

Jan 19, 2024
CVE-2024-21733
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL …

Jan 19, 2024
CVE-2024-23659
6.1 MEDIUM

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

Jan 19, 2024
CVE-2024-23387
4.8 MEDIUM

FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary …

Jan 19, 2024
CVE-2023-50963
6.5 MEDIUM

IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. …

Jan 19, 2024
CVE-2023-47718
4.3 MEDIUM

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Jan 19, 2024
CVE-2023-32337
5.4 MEDIUM

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Jan 19, 2024
CVE-2023-38738
6.8 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native …

Jan 19, 2024
CVE-2023-35020
5.4 MEDIUM

IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Jan 19, 2024
CVE-2024-0695
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of …

Jan 18, 2024
CVE-2024-0693
5.3 MEDIUM

A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of …

Jan 18, 2024
CVE-2023-43816
6.3 MEDIUM

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous …

Jan 18, 2024
CVE-2024-22418
6.5 MEDIUM

Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group …

Jan 18, 2024
CVE-2024-22404
4.1 MEDIUM

Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download …

Jan 18, 2024
CVE-2024-22402
5.4 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to …

Jan 18, 2024
CVE-2024-22401
4.1 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the …

Jan 18, 2024
CVE-2023-51258
5.5 MEDIUM

A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.

Jan 18, 2024
CVE-2023-49943
5.4 MEDIUM

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

Jan 18, 2024
CVE-2023-31274
5.3 MEDIUM

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message …

Jan 18, 2024
CVE-2023-28901
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum …

Jan 18, 2024
CVE-2023-28900
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying …

Jan 18, 2024
CVE-2024-0607
6.6 MEDIUM

A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a …

Jan 18, 2024
CVE-2024-0408
5.5 MEDIUM

A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. …

Jan 18, 2024
CVE-2024-22549
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.

Jan 18, 2024
CVE-2024-22548
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.

Jan 18, 2024
CVE-2023-7153
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …

Jan 18, 2024
CVE-2021-33631
5.5 MEDIUM

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …

Jan 18, 2024
CVE-2021-33630
5.5 MEDIUM

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …

Jan 18, 2024
CVE-2024-0669
6.3 MEDIUM

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …

Jan 18, 2024
CVE-2023-51464
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jan 18, 2024
CVE-2023-51463
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …

Jan 18, 2024
CVE-2024-0580
6.5 MEDIUM

Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …

Jan 18, 2024
CVE-2024-0381
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …

Jan 18, 2024
CVE-2023-6970
6.1 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6958
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2024-0655
5.5 MEDIUM

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …

Jan 18, 2024
CVE-2023-48359
4.4 MEDIUM

In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48358
4.4 MEDIUM

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48357
4.4 MEDIUM

In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48356
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48355
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48354
5.5 MEDIUM

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48353
4.4 MEDIUM

In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.