CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0565
6.8 MEDIUM

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to …

Jan 15, 2024
CVE-2024-0558
4.7 MEDIUM

A vulnerability has been found in DedeBIZ 6.3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/makehtml_freelist_action.php. The manipulation of the …

Jan 15, 2024
CVE-2024-0320
5.4 MEDIUM

Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application …

Jan 15, 2024
CVE-2024-0319
5.4 MEDIUM

Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious …

Jan 15, 2024
CVE-2024-0318
5.4 MEDIUM

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and …

Jan 15, 2024
CVE-2024-0317
5.4 MEDIUM

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' …

Jan 15, 2024
CVE-2024-22207
5.3 MEDIUM

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files …

Jan 15, 2024
CVE-2024-0316
6.8 MEDIUM

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to …

Jan 15, 2024
CVE-2024-0315
6.6 MEDIUM

Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system …

Jan 15, 2024
CVE-2024-0314
5.4 MEDIUM

XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a …

Jan 15, 2024
CVE-2023-6941
4.8 MEDIUM

The Keap Official Opt-in Forms WordPress plugin through 1.0.11 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024
CVE-2023-6843
4.3 MEDIUM

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some …

Jan 15, 2024
CVE-2023-6163
4.8 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jan 15, 2024
CVE-2023-6066
4.3 MEDIUM

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, …

Jan 15, 2024
CVE-2023-6050
6.1 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, …

Jan 15, 2024
CVE-2023-6048
6.5 MEDIUM

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of …

Jan 15, 2024
CVE-2023-4925
4.8 MEDIUM

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 15, 2024
CVE-2023-42135
6.8 MEDIUM

PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. …

Jan 15, 2024
CVE-2023-42134
6.8 MEDIUM

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker …

Jan 15, 2024
CVE-2024-20721
5.5 MEDIUM

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to …

Jan 15, 2024
CVE-2024-20709
5.5 MEDIUM

Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to …

Jan 15, 2024
CVE-2023-5253
5.3 MEDIUM

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated …

Jan 15, 2024
CVE-2023-4001
6.8 MEDIUM

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration …

Jan 15, 2024
CVE-2023-6915
6.2 MEDIUM

A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to …

Jan 15, 2024
CVE-2023-50290
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache …

Jan 15, 2024
CVE-2023-46749
6.5 MEDIUM

Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path …

Jan 15, 2024
CVE-2024-22028
4.6 MEDIUM

Insufficient technical documentation issue exists in thermal camera TMC series all firmware versions. The user of the affected product is not aware of the internally …

Jan 15, 2024
CVE-2024-0548
5.3 MEDIUM

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component SIZE …

Jan 15, 2024
CVE-2024-0547
5.3 MEDIUM

A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component …

Jan 15, 2024
CVE-2024-0546
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. …

Jan 15, 2024
CVE-2024-0545
5.3 MEDIUM

A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation …

Jan 15, 2024
CVE-2024-0543
6.3 MEDIUM

A vulnerability classified as critical has been found in CodeAstro Real Estate Management System up to 1.0. This affects an unknown part of the file …

Jan 15, 2024
CVE-2024-0540
6.3 MEDIUM

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The manipulation …

Jan 15, 2024
CVE-2024-0530
5.5 MEDIUM

A vulnerability was found in CXBSoft Post-Office up to 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jan 15, 2024
CVE-2024-0529
5.5 MEDIUM

A vulnerability has been found in CXBSoft Post-Office up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jan 15, 2024
CVE-2024-0528
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in CXBSoft Post-Office 1.0. Affected is an unknown function of the file /admin/pages/update_go.php of the component …

Jan 15, 2024
CVE-2024-0527
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in CXBSoft Url-shorting up to 1.3.1. This issue affects some unknown processing of the file …

Jan 15, 2024
CVE-2024-0526
5.5 MEDIUM

A vulnerability classified as critical was found in CXBSoft Url-shorting up to 1.3.1. This vulnerability affects unknown code of the file /pages/short_to_long.php of the component …

Jan 15, 2024
CVE-2024-0525
5.5 MEDIUM

A vulnerability classified as critical has been found in CXBSoft Url-shorting up to 1.3.1. This affects an unknown part of the file /pages/long_s_short.php of the …

Jan 15, 2024
CVE-2024-0524
5.5 MEDIUM

A vulnerability was found in CXBSoft Url-shorting up to 1.3.1. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 15, 2024
CVE-2024-0523
6.3 MEDIUM

A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the …

Jan 14, 2024
CVE-2024-0522
4.3 MEDIUM

A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?action=delete of the …

Jan 14, 2024
CVE-2024-0505
5.5 MEDIUM

A vulnerability was found in ZhongFuCheng3y Austin 1.0 and classified as critical. This issue affects the function getFile of the file com/java3y/austin/web/controller/MaterialController.java of the component …

Jan 13, 2024
CVE-2024-0502
4.7 MEDIUM

A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 13, 2024
CVE-2024-0498
6.3 MEDIUM

A vulnerability was found in Project Worlds Lawyer Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 13, 2024
CVE-2024-0497
6.3 MEDIUM

A vulnerability was found in Campcodes Student Information System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Users.php?f=save. …

Jan 13, 2024
CVE-2024-0496
6.3 MEDIUM

A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the …

Jan 13, 2024
CVE-2024-0495
6.3 MEDIUM

A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file party_submit.php of the …

Jan 13, 2024
CVE-2024-0494
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the …

Jan 13, 2024
CVE-2024-0493
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the …

Jan 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.