CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29489
5.5 MEDIUM

Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.

Mar 28, 2024
CVE-2024-29316
6.3 MEDIUM

NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs for the Admin group via "isadmin":true.

Mar 28, 2024
CVE-2024-28714
8.1 HIGH

SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.

Mar 28, 2024
CVE-2024-28456
5.4 MEDIUM

Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the …

Mar 28, 2024
CVE-2024-24407
5.3 MEDIUM

SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.

Mar 28, 2024
CVE-2023-50969
9.8 CRITICAL

Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

Mar 28, 2024
CVE-2023-33528
6.1 MEDIUM

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

Mar 28, 2024
CVE-2021-31156
7.5 HIGH

Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve partial access to data.

Mar 28, 2024
CVE-2023-25341
6.5 MEDIUM

A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user …

Mar 28, 2024
CVE-2024-23727
8.4 HIGH

The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to …

Mar 28, 2024
CVE-2024-28091
6.1 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User Defined Service in managed_services_add.asp (the victim …

Mar 28, 2024
CVE-2024-28090
5.4 MEDIUM

Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via User name in dyn_dns.asp.

Mar 28, 2024
CVE-2024-25506
6.5 MEDIUM

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

Mar 28, 2024
CVE-2024-3019
8.8 HIGH

A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the …

Mar 28, 2024
CVE-2024-31065
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.

Mar 28, 2024
CVE-2024-31064
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

Mar 28, 2024
CVE-2024-31063
6.4 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.

Mar 28, 2024
CVE-2024-31062
6.3 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.

Mar 28, 2024
CVE-2024-31061
6.1 MEDIUM

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field.

Mar 28, 2024
CVE-2024-2947
7.3 HIGH

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, …

Mar 28, 2024
CVE-2024-28713
9.8 CRITICAL

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

Mar 28, 2024
CVE-2024-27719
6.1 MEDIUM

A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to …

Mar 28, 2024
CVE-2024-25971
5.5 MEDIUM

Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2024-25963
5.9 MEDIUM

Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25960
7.3 HIGH

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25955
7.2 HIGH

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of …

Mar 28, 2024
CVE-2024-25954
5.3 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial …

Mar 28, 2024
CVE-2024-25953
6.0 MEDIUM

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25952
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25946
7.2 HIGH

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of …

Mar 28, 2024
CVE-2024-25961
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2024-25959
7.9 HIGH

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit …

Mar 28, 2024
CVE-2023-42974
7.0 HIGH

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, …

Mar 28, 2024
CVE-2023-42962
7.5 HIGH

This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker …

Mar 28, 2024
CVE-2023-42956
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web …

Mar 28, 2024
CVE-2023-42950
8.8 HIGH

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, …

Mar 28, 2024
CVE-2023-42947
8.6 HIGH

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, …

Mar 28, 2024
CVE-2023-42936
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42931
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain …

Mar 28, 2024
CVE-2023-42930
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be …

Mar 28, 2024
CVE-2023-42913
8.8 HIGH

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full …

Mar 28, 2024
CVE-2023-42896
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42893
5.5 MEDIUM

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS …

Mar 28, 2024
CVE-2023-42892
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local …

Mar 28, 2024
CVE-2023-40390
5.5 MEDIUM

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be …

Mar 28, 2024
CVE-2024-3042
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The …

Mar 28, 2024
CVE-2024-3041
6.3 MEDIUM

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. …

Mar 28, 2024
CVE-2024-3040
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. …

Mar 28, 2024
CVE-2024-3039
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the …

Mar 28, 2024
CVE-2024-31140
4.1 MEDIUM

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.