CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22352
6.5 MEDIUM

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 280361.

Mar 21, 2024
CVE-2024-1908
6.3 MEDIUM

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitHub Connect download token to …

Mar 21, 2024
CVE-2024-1503
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Mar 21, 2024
CVE-2024-1502
5.4 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Mar 21, 2024
CVE-2024-1450
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.10 …

Mar 21, 2024
CVE-2024-1326
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all versions up to, and including, 2.6.2 …

Mar 21, 2024
CVE-2024-1278
6.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 21, 2024
CVE-2024-1214
4.3 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1213
5.4 MEDIUM

The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Mar 21, 2024
CVE-2024-1202
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass.This issue affects Octopod: before v1. NOTE: The vendor was contacted and it was …

Mar 21, 2024
CVE-2024-1142
5.4 MEDIUM

Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files via a specially crafted request. Version 171 …

Mar 21, 2024
CVE-2024-0966
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-6500
6.4 MEDIUM

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.9 …

Mar 21, 2024
CVE-2023-49985
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49984
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49983
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 21, 2024
CVE-2023-49982
8.8 HIGH

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and …

Mar 21, 2024
CVE-2023-49981
7.5 HIGH

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49980
7.5 HIGH

A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49979
7.5 HIGH

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49978
8.8 HIGH

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

Mar 21, 2024
CVE-2023-38825
6.5 MEDIUM

SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.

Mar 21, 2024
CVE-2023-35899
7.0 HIGH

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV …

Mar 21, 2024
CVE-2022-4963
5.5 MEDIUM

A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function …

Mar 21, 2024
CVE-2020-26942
9.1 CRITICAL

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting …

Mar 21, 2024
CVE-2024-2748
4.3 MEDIUM

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting …

Mar 21, 2024
CVE-2024-28916
8.8 HIGH

Xbox Gaming Services Elevation of Privilege Vulnerability

Mar 21, 2024
CVE-2024-2469
8.0 HIGH

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server …

Mar 20, 2024
CVE-2024-2443
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Mar 20, 2024
CVE-2024-2720
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Complete Online DJ Booking System 1.0. Affected by this vulnerability is an unknown functionality of the …

Mar 20, 2024
CVE-2024-29026
8.2 HIGH

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows …

Mar 20, 2024
CVE-2024-24050
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.

Mar 20, 2024
CVE-2024-2719
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. …

Mar 20, 2024
CVE-2024-2718
3.5 LOW

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Mar 20, 2024
CVE-2024-2717
3.5 LOW

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

Mar 20, 2024
CVE-2024-29474
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.

Mar 20, 2024
CVE-2024-29473
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.

Mar 20, 2024
CVE-2024-29472
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

Mar 20, 2024
CVE-2024-29471
5.4 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

Mar 20, 2024
CVE-2024-29470
6.1 MEDIUM

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

Mar 20, 2024
CVE-2024-29469
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Mar 20, 2024
CVE-2024-29037
9.1 CRITICAL

datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, …

Mar 20, 2024
CVE-2024-29036
4.3 MEDIUM

Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access …

Mar 20, 2024
CVE-2024-29033
7.5 HIGH

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. …

Mar 20, 2024
CVE-2024-29032
5.3 MEDIUM

Qiskit IBM Runtime is an environment that streamlines quantum computations and provides optimal implementations of the Qiskit quantum computing SDK. Starting in version 0.1.0 and …

Mar 20, 2024
CVE-2024-29018
5.9 MEDIUM

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. …

Mar 20, 2024
CVE-2024-25294
9.1 CRITICAL

An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.

Mar 20, 2024
CVE-2024-2716
3.5 LOW

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0. It has been classified as problematic. This affects an unknown part of the …

Mar 20, 2024
CVE-2024-2715
3.5 LOW

A vulnerability was found in Campcodes Complete Online DJ Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of …

Mar 20, 2024
CVE-2024-2714
6.3 MEDIUM

A vulnerability has been found in Campcodes Complete Online DJ Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.