CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0492
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php of …

Jan 13, 2024
CVE-2024-0491
5.3 MEDIUM

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation …

Jan 13, 2024
CVE-2024-0490
5.3 MEDIUM

A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 13, 2024
CVE-2024-0489
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jan 13, 2024
CVE-2024-0488
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jan 13, 2024
CVE-2024-0487
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 13, 2024
CVE-2024-0486
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 13, 2024
CVE-2024-0485
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Fighting Cock Information System 1.0. Affected is an unknown function of the file admin/pages/tables/add_con.php. …

Jan 13, 2024
CVE-2024-0484
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Fighting Cock Information System 1.0. This issue affects some unknown processing of the …

Jan 13, 2024
CVE-2024-0483
6.3 MEDIUM

A vulnerability classified as critical was found in Taokeyun up to 1.0.5. This vulnerability affects the function index of the file application/index/controller/app/Task.php of the component …

Jan 13, 2024
CVE-2024-0482
6.3 MEDIUM

A vulnerability classified as critical has been found in Taokeyun up to 1.0.5. This affects the function index of the file application/index/controller/app/Video.php of the component …

Jan 13, 2024
CVE-2024-0481
6.3 MEDIUM

A vulnerability was found in Taokeyun up to 1.0.5. It has been rated as critical. Affected by this issue is the function shopGoods of the …

Jan 13, 2024
CVE-2024-22209
6.4 MEDIUM

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints …

Jan 13, 2024
CVE-2024-21640
5.4 MEDIUM

Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read …

Jan 13, 2024
CVE-2024-0251
6.1 MEDIUM

The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in all versions up to, and including, 2.96 …

Jan 13, 2024
CVE-2024-0478
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/edit_chicken.php. …

Jan 13, 2024
CVE-2024-0477
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/action/update-deworm.php. …

Jan 13, 2024
CVE-2023-51071
6.5 MEDIUM

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a …

Jan 13, 2024
CVE-2023-51068
5.4 MEDIUM

An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51067
6.1 MEDIUM

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51064
6.1 MEDIUM

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

Jan 13, 2024
CVE-2023-51062
5.3 MEDIUM

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log …

Jan 13, 2024
CVE-2023-51805
6.5 MEDIUM

SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java …

Jan 13, 2024
CVE-2023-50072
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on …

Jan 13, 2024
CVE-2024-22137
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch Constant Contact Forms by MailMunch allows Stored XSS.This issue affects Constant Contact …

Jan 13, 2024
CVE-2024-0475
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 13, 2024
CVE-2024-23301
5.5 MEDIUM

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable …

Jan 12, 2024
CVE-2024-21639
5.3 MEDIUM

CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared …

Jan 12, 2024
CVE-2024-0473
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Dormitory Management System 1.0. Affected is an unknown function of the file comment.php. The manipulation …

Jan 12, 2024
CVE-2022-4962
4.3 MEDIUM

A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the …

Jan 12, 2024
CVE-2024-21655
4.3 MEDIUM

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to …

Jan 12, 2024
CVE-2024-21654
4.8 MEDIUM

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email …

Jan 12, 2024
CVE-2024-0471
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jan 12, 2024
CVE-2024-0470
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jan 12, 2024
CVE-2024-0469
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 12, 2024
CVE-2024-0468
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2023-49801
4.2 MEDIUM

Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` …

Jan 12, 2024
CVE-2010-10011
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. …

Jan 12, 2024
CVE-2024-0466
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the …

Jan 12, 2024
CVE-2024-0464
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Faculty Clearance 1.0. This affects an unknown part of the file delete_faculty.php of the …

Jan 12, 2024
CVE-2023-6683
6.5 MEDIUM

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and …

Jan 12, 2024
CVE-2023-31034
6.6 MEDIUM

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A …

Jan 12, 2024
CVE-2023-31033
6.8 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . …

Jan 12, 2024
CVE-2023-31031
4.2 MEDIUM

NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A …

Jan 12, 2024
CVE-2023-31025
6.5 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to …

Jan 12, 2024
CVE-2024-0463
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 12, 2024
CVE-2024-0462
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2024-0461
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php …

Jan 12, 2024
CVE-2023-28899
4.7 MEDIUM

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service …

Jan 12, 2024
CVE-2024-22494
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.