CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22493
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-22492
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-0460
6.3 MEDIUM

A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/student-print.php. The …

Jan 12, 2024
CVE-2024-0459
4.7 MEDIUM

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. …

Jan 12, 2024
CVE-2023-51978
6.5 MEDIUM

In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.

Jan 12, 2024
CVE-2023-28898
5.3 MEDIUM

The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows …

Jan 12, 2024
CVE-2023-28897
4.0 MEDIUM

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III …

Jan 12, 2024
CVE-2023-49260
6.1 MEDIUM

An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used together with …

Jan 12, 2024
CVE-2023-49258
6.1 MEDIUM

User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui/terminal_tool.cgi" in the …

Jan 12, 2024
CVE-2023-6955
6.6 MEDIUM

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. …

Jan 12, 2024
CVE-2023-0437
5.3 MEDIUM

When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects …

Jan 12, 2024
CVE-2023-51806
5.4 MEDIUM

File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

Jan 12, 2024
CVE-2023-51790
6.1 MEDIUM

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

Jan 12, 2024
CVE-2023-50920
5.5 MEDIUM

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session …

Jan 12, 2024
CVE-2023-40362
4.3 MEDIUM

An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors …

Jan 12, 2024
CVE-2024-22027
6.5 MEDIUM

Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack …

Jan 12, 2024
CVE-2024-23179
6.1 MEDIUM

An issue was discovered in the GlobalBlocking extension in MediaWiki before 1.40.2. For a Special:GlobalBlock?uselang=x-xss URI, i18n-based XSS can occur via the parentheses message. This …

Jan 12, 2024
CVE-2024-23178
5.4 MEDIUM

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

Jan 12, 2024
CVE-2024-23177
6.1 MEDIUM

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

Jan 12, 2024
CVE-2024-23174
5.4 MEDIUM

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23173
6.1 MEDIUM

An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows …

Jan 12, 2024
CVE-2024-23172
5.4 MEDIUM

An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23171
5.4 MEDIUM

An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows …

Jan 12, 2024
CVE-2022-4961
5.5 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 12, 2024
CVE-2022-48619
5.5 MEDIUM

An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the …

Jan 12, 2024
CVE-2024-0454
6.0 MEDIUM

ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows …

Jan 12, 2024
CVE-2023-52339
6.5 MEDIUM

In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.

Jan 12, 2024
CVE-2024-21617
6.5 MEDIUM

An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading …

Jan 12, 2024
CVE-2024-21613
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Jan 12, 2024
CVE-2024-21607
5.3 MEDIUM

An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024
CVE-2024-21603
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker …

Jan 12, 2024
CVE-2024-21601
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series …

Jan 12, 2024
CVE-2024-21600
6.5 MEDIUM

An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, …

Jan 12, 2024
CVE-2024-21599
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21597
5.3 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, …

Jan 12, 2024
CVE-2024-21596
5.3 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based …

Jan 12, 2024
CVE-2024-21594
5.5 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a …

Jan 12, 2024
CVE-2024-21587
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21585
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, …

Jan 12, 2024
CVE-2023-36842
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to …

Jan 12, 2024
CVE-2024-21982
4.8 MEDIUM

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when …

Jan 12, 2024
CVE-2024-0443
5.5 MEDIUM

A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a …

Jan 12, 2024
CVE-2024-21337
5.2 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 11, 2024
CVE-2024-20675
6.3 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Jan 11, 2024
CVE-2024-0426
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2023-7226
6.3 MEDIUM

A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of …

Jan 11, 2024
CVE-2023-50129
6.5 MEDIUM

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024
CVE-2023-50128
5.3 MEDIUM

The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker …

Jan 11, 2024
CVE-2023-50127
5.9 MEDIUM

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an …

Jan 11, 2024
CVE-2023-50126
6.5 MEDIUM

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.