CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42797
6.6 MEDIUM

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration …

Jan 9, 2024
CVE-2024-22368
5.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation …

Jan 9, 2024
CVE-2023-6149
5.7 MEDIUM

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission …

Jan 9, 2024
CVE-2023-6148
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-50974
5.5 MEDIUM

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as …

Jan 9, 2024
CVE-2023-6147
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-6842
4.4 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 9, 2024
CVE-2023-6830
6.5 MEDIUM

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject …

Jan 9, 2024
CVE-2023-6788
5.4 MEDIUM

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is …

Jan 9, 2024
CVE-2023-6594
4.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 …

Jan 9, 2024
CVE-2024-22124
4.1 MEDIUM

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, …

Jan 9, 2024
CVE-2024-21738
4.1 MEDIUM

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges …

Jan 9, 2024
CVE-2024-21736
6.4 MEDIUM

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered …

Jan 9, 2024
CVE-2023-36629
5.5 MEDIUM

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

Jan 9, 2024
CVE-2023-27000
6.1 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion …

Jan 9, 2024
CVE-2023-26998
5.4 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

Jan 9, 2024
CVE-2023-46906
4.9 MEDIUM

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone …

Jan 9, 2024
CVE-2022-36352
6.3 MEDIUM

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a …

Jan 8, 2024
CVE-2022-34344
5.4 MEDIUM

Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This …

Jan 8, 2024
CVE-2023-52198
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michiel van Eerd Private Google Calendars allows Stored XSS.This issue affects Private Google …

Jan 8, 2024
CVE-2023-52197
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Impactpixel Ads Invalid Click Protection allows Stored XSS.This issue affects Ads Invalid Click …

Jan 8, 2024
CVE-2023-51508
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & …

Jan 8, 2024
CVE-2023-51490
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security …

Jan 8, 2024
CVE-2023-51408
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue …

Jan 8, 2024
CVE-2023-51406
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FastDup – Fastest WordPress Migration & Duplicator.This issue affects FastDup – Fastest WordPress …

Jan 8, 2024
CVE-2023-27739
6.1 MEDIUM

easyXDM 2.5 allows XSS via the xdm_e parameter.

Jan 8, 2024
CVE-2022-45354
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60.

Jan 8, 2024
CVE-2023-52271
6.5 MEDIUM

The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via an IOCTL (which will be named …

Jan 8, 2024
CVE-2023-52216
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yevhen Kotelnytskyi JS & CSS Script Optimizer.This issue affects JS & CSS Script Optimizer: from n/a through 0.3.3.

Jan 8, 2024
CVE-2023-52203
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a …

Jan 8, 2024
CVE-2023-51246
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the …

Jan 8, 2024
CVE-2023-6627
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can …

Jan 8, 2024
CVE-2023-6555
6.1 MEDIUM

The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jan 8, 2024
CVE-2023-6529
6.1 MEDIUM

The WP VR WordPress plugin before 8.3.15 does not authorisation and CSRF in a function hooked to admin_init, allowing unauthenticated users to downgrade the plugin, …

Jan 8, 2024
CVE-2023-6161
6.1 MEDIUM

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2024
CVE-2023-6141
5.4 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-6139
6.5 MEDIUM

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with …

Jan 8, 2024
CVE-2023-5911
4.8 MEDIUM

The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high …

Jan 8, 2024
CVE-2023-52222
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WooCommerce.This issue affects WooCommerce: from n/a through 8.2.2.

Jan 8, 2024
CVE-2023-52208
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.

Jan 8, 2024
CVE-2023-1032
4.7 MEDIUM

The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in …

Jan 8, 2024
CVE-2022-2602
5.3 MEDIUM

io_uring UAF, Unix SCM garbage collection

Jan 8, 2024
CVE-2022-2588
5.3 MEDIUM

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if …

Jan 8, 2024
CVE-2022-2586
5.3 MEDIUM KEV

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that …

Jan 8, 2024
CVE-2022-2585
5.3 MEDIUM

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a …

Jan 8, 2024
CVE-2024-21745
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Laybuy Laybuy Payment Extension for WooCommerce allows Stored XSS.This issue affects Laybuy Payment …

Jan 8, 2024
CVE-2024-21744
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mapster Technology Inc. Mapster WP Maps allows Stored XSS.This issue affects Mapster WP …

Jan 8, 2024
CVE-2024-21647
5.9 MEDIUM

Puma is a web server for Ruby/Rack applications built for parallelism. Prior to version 6.4.2, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies …

Jan 8, 2024
CVE-2024-21645
5.3 MEDIUM

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in `pyload` allowing any unauthenticated actor to …

Jan 8, 2024
CVE-2023-51701
5.3 MEDIUM

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming …

Jan 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.