CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20950
6.1 MEDIUM

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Jan 16, 2024
CVE-2024-20948
6.1 MEDIUM

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Setup, Admin). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Jan 16, 2024
CVE-2024-20946
5.5 MEDIUM

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged …

Jan 16, 2024
CVE-2024-20944
5.4 MEDIUM

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low …

Jan 16, 2024
CVE-2024-20942
6.1 MEDIUM

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: LOV). Supported versions that are affected are 11.5, 12.1 and …

Jan 16, 2024
CVE-2024-20940
6.1 MEDIUM

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Create, Update, Authoring Flow). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Jan 16, 2024
CVE-2024-20938
6.1 MEDIUM

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker …

Jan 16, 2024
CVE-2024-20936
6.1 MEDIUM

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated …

Jan 16, 2024
CVE-2024-20934
6.1 MEDIUM

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20930
6.3 MEDIUM

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Content Access SDK, Image Export SDK, PDF Export SDK, HTML Export SDK). …

Jan 16, 2024
CVE-2024-20928
6.1 MEDIUM

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20926
5.9 MEDIUM

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting). Supported versions that are …

Jan 16, 2024
CVE-2024-20908
6.1 MEDIUM

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability …

Jan 16, 2024
CVE-2024-20906
4.8 MEDIUM

Vulnerability in the Integrated Lights Out Manager (ILOM) product of Oracle Systems (component: System Management). Supported versions that are affected are 3, 4 and 5. …

Jan 16, 2024
CVE-2024-20904
5.0 MEDIUM

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily …

Jan 16, 2024
CVE-2024-0601
6.3 MEDIUM

A vulnerability was found in ZhongFuCheng3y Austin 1.0. It has been rated as critical. Affected by this issue is the function getRemoteUrl2File of the file …

Jan 16, 2024
CVE-2023-52068
6.1 MEDIUM

kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.

Jan 16, 2024
CVE-2023-36236
4.8 MEDIUM

Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

Jan 16, 2024
CVE-2023-48926
5.3 MEDIUM

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

Jan 16, 2024
CVE-2023-6335
6.4 MEDIUM

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2023-6334
5.3 MEDIUM

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buffers.This issue affects Workforce Access: …

Jan 16, 2024
CVE-2024-22491
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the post/save content parameter.

Jan 16, 2024
CVE-2024-0507
6.5 MEDIUM

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management …

Jan 16, 2024
CVE-2023-7234
5.3 MEDIUM

OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.

Jan 16, 2024
CVE-2023-37523
5.6 MEDIUM

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious …

Jan 16, 2024
CVE-2024-0579
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation …

Jan 16, 2024
CVE-2023-4969
6.5 MEDIUM

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local …

Jan 16, 2024
CVE-2024-0239
6.1 MEDIUM

The Contact Form 7 Connector WordPress plugin before 1.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Jan 16, 2024
CVE-2024-0238
6.1 MEDIUM

The EventON Premium WordPress plugin before 4.5.6, EventON WordPress plugin before 2.2.8 do not have authorisation in an AJAX action, and does not ensure that …

Jan 16, 2024
CVE-2024-0237
5.3 MEDIUM

The EventON WordPress plugin through 4.5.8, EventON WordPress plugin before 2.2.7 do not have authorisation in some AJAX actions, allowing unauthenticated users to update virtual …

Jan 16, 2024
CVE-2024-0236
5.3 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the …

Jan 16, 2024
CVE-2024-0235
5.3 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email …

Jan 16, 2024
CVE-2024-0233
6.1 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, …

Jan 16, 2024
CVE-2024-0187
6.1 MEDIUM

The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to …

Jan 16, 2024
CVE-2023-7154
4.8 MEDIUM

The Hubbub Lite (formerly Grow Social) WordPress plugin before 1.32.0 does not sanitise and escape some of its settings, which could allow high privilege users …

Jan 16, 2024
CVE-2023-7151
6.1 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.2 does not sanitise and escape the page parameter before outputting it back in an attribute, leading …

Jan 16, 2024
CVE-2023-7125
4.3 MEDIUM

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile …

Jan 16, 2024
CVE-2023-7084
5.4 MEDIUM

The Voting Record WordPress plugin through 2.0 is missing sanitisation as well as escaping, which could allow any authenticated users, such as subscriber to perform …

Jan 16, 2024
CVE-2023-7083
5.4 MEDIUM

The Voting Record WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jan 16, 2024
CVE-2023-6824
6.5 MEDIUM

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve …

Jan 16, 2024
CVE-2023-6741
4.3 MEDIUM

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit …

Jan 16, 2024
CVE-2023-6732
4.8 MEDIUM

The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 16, 2024
CVE-2023-6592
5.3 MEDIUM

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

Jan 16, 2024
CVE-2023-6292
4.3 MEDIUM

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 16, 2024
CVE-2023-6046
4.8 MEDIUM

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 16, 2024
CVE-2023-6005
4.8 MEDIUM

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege …

Jan 16, 2024
CVE-2023-5558
6.1 MEDIUM

The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 16, 2024
CVE-2023-4757
5.4 MEDIUM

The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before …

Jan 16, 2024
CVE-2023-45237
5.3 MEDIUM

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and …

Jan 16, 2024
CVE-2023-45236
5.8 MEDIUM

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.