CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11244
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code of the file /editar-cliente.php. The manipulation of the argument …

Nov 15, 2024
CVE-2023-20094
4.3 MEDIUM

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists …

Nov 15, 2024
CVE-2023-20093
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20092
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20091
5.1 MEDIUM

A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20090
6.7 MEDIUM

A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability …

Nov 15, 2024
CVE-2023-20060
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against …

Nov 15, 2024
CVE-2023-20039
5.5 MEDIUM

A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that …

Nov 15, 2024
CVE-2023-20036
9.9 CRITICAL

A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying …

Nov 15, 2024
CVE-2023-20004
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2022-20948
5.4 MEDIUM

A vulnerability in the web management interface of Cisco BroadWorks Hosted Thin Receptionist could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack …

Nov 15, 2024
CVE-2022-20939
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. …

Nov 15, 2024
CVE-2022-20931
6.5 MEDIUM

A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version …

Nov 15, 2024
CVE-2022-20871
6.3 MEDIUM

A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform …

Nov 15, 2024
CVE-2022-20853
7.4 HIGH

A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) …

Nov 15, 2024
CVE-2022-20849
6.1 MEDIUM

A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the …

Nov 15, 2024
CVE-2022-20846
4.3 MEDIUM

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload …

Nov 15, 2024
CVE-2022-20845
6.0 MEDIUM

A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in …

Nov 15, 2024
CVE-2022-20814
7.4 HIGH

A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability …

Nov 15, 2024
CVE-2022-20793
6.8 MEDIUM

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a …

Nov 15, 2024
CVE-2022-20766
5.3 MEDIUM

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS …

Nov 15, 2024
CVE-2022-20685
7.5 HIGH

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …

Nov 15, 2024
CVE-2022-20663
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting …

Nov 15, 2024
CVE-2022-20657
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user …

Nov 15, 2024
CVE-2022-20656
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an …

Nov 15, 2024
CVE-2022-20655
8.8 HIGH

A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command …

Nov 15, 2024
CVE-2022-20654
6.1 MEDIUM

A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user …

Nov 15, 2024
CVE-2022-20652
6.5 MEDIUM

A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker to inject arbitrary commands to …

Nov 15, 2024
CVE-2022-20649
8.1 HIGH

A vulnerability in Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges in the …

Nov 15, 2024
CVE-2022-20648
5.3 MEDIUM

A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in …

Nov 15, 2024
CVE-2022-20634
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This …

Nov 15, 2024
CVE-2022-20631
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the …

Nov 15, 2024
CVE-2022-20626
5.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Access Registrar Appliance could allow an authenticated, remote attacker to conduct a cross-site scripting attack against …

Nov 15, 2024
CVE-2024-50986
7.3 HIGH

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

Nov 15, 2024
CVE-2024-48068
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Shenzhen Landray Software Co.,LTD Landray EKP v16 and earlier allows attackers to execute arbitrary web scripts or HTML via …

Nov 15, 2024
CVE-2024-43189
5.9 MEDIUM

IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Nov 15, 2024
CVE-2024-41785
6.1 MEDIUM

IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web …

Nov 15, 2024
CVE-2024-20373
5.3 MEDIUM

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS …

Nov 15, 2024
CVE-2024-11243
4.3 MEDIUM

A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown part of the file /signup.php. The manipulation …

Nov 15, 2024
CVE-2024-11242
4.7 MEDIUM

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ad_list.php?action=pass …

Nov 15, 2024
CVE-2024-11241
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Nov 15, 2024
CVE-2023-20154
9.1 CRITICAL

A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges. …

Nov 15, 2024
CVE-2023-20125
8.6 HIGH

A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of …

Nov 15, 2024
CVE-2024-11240
3.5 LOW

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of …

Nov 15, 2024
CVE-2024-11239
5.4 MEDIUM

A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the function deleteFile of the file /sys/common/import.do?method=deleteFile …

Nov 15, 2024
CVE-2024-11238
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPreviewFile of the file /sys/ui/sys_ui_component/sysUiComponent.do?method=delPreviewFile. The …

Nov 15, 2024
CVE-2024-11237
7.5 HIGH

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the …

Nov 15, 2024
CVE-2023-4348

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 15, 2024
CVE-2024-1240
6.1 MEDIUM

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An …

Nov 15, 2024
CVE-2024-1097
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.