CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50717
5.7 MEDIUM

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with …

May 14, 2024
CVE-2023-49781
7.3 HIGH

NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The …

May 14, 2024
CVE-2023-47712
7.8 HIGH

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. …

May 14, 2024
CVE-2023-47711
2.7 LOW

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force …

May 14, 2024
CVE-2023-47709
9.1 CRITICAL

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially …

May 14, 2024
CVE-2023-46870
7.3 HIGH

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers …

May 14, 2024
CVE-2023-43040
6.5 MEDIUM

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM …

May 14, 2024
CVE-2023-42955
4.9 MEDIUM

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator …

May 14, 2024
CVE-2023-38264
5.9 MEDIUM

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack …

May 14, 2024
CVE-2023-37526
6.5 MEDIUM

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which …

May 14, 2024
CVE-2023-29881
6.5 MEDIUM

phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

May 14, 2024
CVE-2023-26863

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 14, 2024
CVE-2023-26566
8.6 HIGH

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make …

May 14, 2024
CVE-2022-4967
7.7 HIGH

strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate …

May 14, 2024
CVE-2022-32510
7.1 HIGH

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative …

May 14, 2024
CVE-2022-32509
8.8 HIGH

An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This …

May 14, 2024
CVE-2022-32508
7.5 HIGH

An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the …

May 14, 2024
CVE-2022-32507
8.8 HIGH

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, …

May 14, 2024
CVE-2022-32506
6.4 MEDIUM

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features …

May 14, 2024
CVE-2022-32505
7.1 HIGH

An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality …

May 14, 2024
CVE-2022-32504
9.8 CRITICAL

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by …

May 14, 2024
CVE-2022-32503
7.6 HIGH

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to …

May 14, 2024
CVE-2022-32502
6.3 MEDIUM

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service …

May 14, 2024
CVE-2020-36662

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 14, 2024
CVE-2020-18305
8.0 HIGH

Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing …

May 14, 2024
CVE-2024-34257
9.8 CRITICAL

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

May 8, 2024
CVE-2024-34244
7.5 HIGH

libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, …

May 8, 2024
CVE-2024-33382
5.3 MEDIUM

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

May 8, 2024
CVE-2024-25533
9.4 CRITICAL

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write …

May 8, 2024
CVE-2024-25532
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.

May 8, 2024
CVE-2024-25528
5.9 MEDIUM

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.

May 8, 2024
CVE-2024-31961
9.8 CRITICAL

A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbitrary SQL commands via the level2 parameter.

May 8, 2024
CVE-2024-28971
3.5 LOW

Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit …

May 8, 2024
CVE-2024-25531
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.

May 8, 2024
CVE-2024-25530
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.

May 8, 2024
CVE-2024-25529
9.8 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_office_file_history_show.aspx.

May 8, 2024
CVE-2024-25527
9.4 CRITICAL

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.

May 8, 2024
CVE-2024-24908
6.5 MEDIUM

Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker with high privileges could potentially exploit …

May 8, 2024
CVE-2024-24788
5.9 MEDIUM

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

May 8, 2024
CVE-2024-24787
6.4 MEDIUM

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of …

May 8, 2024
CVE-2024-22460
2.2 LOW

Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacker with high privileges could potentially exploit this vulnerability, leading to …

May 8, 2024
CVE-2024-4654
6.3 MEDIUM

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file …

May 8, 2024
CVE-2024-4653
6.3 MEDIUM

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the …

May 8, 2024
CVE-2024-3951
7.1 HIGH

PTC Codebeamer is vulnerable to a cross site scripting vulnerability that could allow an attacker to inject and execute malicious code.

May 8, 2024
CVE-2024-34347
8.3 HIGH

@hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript sandbox that uses the …

May 8, 2024
CVE-2024-33612
6.8 MEDIUM

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions …

May 8, 2024
CVE-2024-33608
7.5 HIGH

When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached …

May 8, 2024
CVE-2024-33604
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context …

May 8, 2024
CVE-2024-32980
9.1 CRITICAL

Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` …

May 8, 2024
CVE-2024-32761
6.5 MEDIUM

Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak …

May 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.