CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0361
5.5 MEDIUM

A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation …

Jan 10, 2024
CVE-2024-0360
5.5 MEDIUM

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jan 10, 2024
CVE-2024-0358
5.3 MEDIUM

A vulnerability was found in DeShang DSO2O up to 4.1.0. It has been classified as critical. This affects an unknown part of the file /install/install.php. …

Jan 10, 2024
CVE-2024-0357
5.5 MEDIUM

A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of …

Jan 10, 2024
CVE-2024-0356
4.3 MEDIUM

A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles …

Jan 10, 2024
CVE-2024-0355
5.5 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of …

Jan 10, 2024
CVE-2024-0354
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file …

Jan 10, 2024
CVE-2023-47997
6.5 MEDIUM

An issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to cause a denial of service.

Jan 10, 2024
CVE-2023-47996
6.5 MEDIUM

An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.

Jan 9, 2024
CVE-2023-47995
6.5 MEDIUM

Memory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers to cause a denial of service.

Jan 9, 2024
CVE-2023-47993
6.5 MEDIUM

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

Jan 9, 2024
CVE-2024-0348
4.3 MEDIUM

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the component File …

Jan 9, 2024
CVE-2023-6476
6.5 MEDIUM

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and …

Jan 9, 2024
CVE-2023-5770
5.3 MEDIUM

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body …

Jan 9, 2024
CVE-2023-50136
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table.

Jan 9, 2024
CVE-2023-38827
6.1 MEDIUM

Cross Site Scripting vulnerability in Follet School Solutions Destiny v.20_0_1_AU4 and later allows a remote attacker to run arbitrary code via presentonesearchresultsform.do.

Jan 9, 2024
CVE-2024-0345
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of …

Jan 9, 2024
CVE-2024-0344
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of …

Jan 9, 2024
CVE-2024-21664
4.3 MEDIUM

jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` field …

Jan 9, 2024
CVE-2024-0343
4.3 MEDIUM

A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component …

Jan 9, 2024
CVE-2024-0342
6.3 MEDIUM

A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /app/api/controller/default/Sqlite.php. The manipulation of …

Jan 9, 2024
CVE-2024-21668
4.4 MEDIUM

react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the react-native-mmkv logged the optional encryption key for …

Jan 9, 2024
CVE-2024-21319
6.8 MEDIUM

Microsoft Identity Denial of service vulnerability

Jan 9, 2024
CVE-2024-21320
6.5 MEDIUM

Windows Themes Spoofing Vulnerability

Jan 9, 2024
CVE-2024-21316
6.1 MEDIUM

Windows Server Key Distribution Service Security Feature Bypass

Jan 9, 2024
CVE-2024-21314
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21313
5.3 MEDIUM

Windows TCP/IP Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21311
5.5 MEDIUM

Windows Cryptographic Services Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21306
5.7 MEDIUM

Microsoft Bluetooth Driver Spoofing Vulnerability

Jan 9, 2024
CVE-2024-21305
4.4 MEDIUM

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20699
5.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20694
5.5 MEDIUM

Windows CoreMessaging Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20692
5.7 MEDIUM

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20691
4.7 MEDIUM

Windows Themes Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20690
6.5 MEDIUM

Windows Nearby Sharing Spoofing Vulnerability

Jan 9, 2024
CVE-2024-20680
6.5 MEDIUM

Windows Message Queuing Client (MSMQC) Information Disclosure

Jan 9, 2024
CVE-2024-20666
6.6 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20664
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20663
6.5 MEDIUM

Windows Message Queuing Client (MSMQC) Information Disclosure

Jan 9, 2024
CVE-2024-20662
4.9 MEDIUM

Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20660
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20655
6.6 MEDIUM

Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-0340
4.4 MEDIUM

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and …

Jan 9, 2024
CVE-2024-0226
4.8 MEDIUM

Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.

Jan 9, 2024
CVE-2024-22165
6.5 MEDIUM

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed …

Jan 9, 2024
CVE-2024-22164
4.3 MEDIUM

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The …

Jan 9, 2024
CVE-2023-6129
6.5 MEDIUM

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based …

Jan 9, 2024
CVE-2023-7223
5.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 9, 2024
CVE-2022-28975
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jan 9, 2024
CVE-2024-22370
4.6 MEDIUM

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.