CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28868
3.7 LOW

Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user …

Mar 20, 2024
CVE-2024-28231
9.6 CRITICAL

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, …

Mar 20, 2024
CVE-2024-28179
9.0 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. Prior to versions 3.2.3 and …

Mar 20, 2024
CVE-2024-27286
6.5 MEDIUM

Zulip is an open-source team collaboration tool. When a user moves a Zulip message, they have the option to move all messages in the topic, …

Mar 20, 2024
CVE-2024-23721
7.5 HIGH

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports …

Mar 20, 2024
CVE-2024-2711
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by this issue is the function addWifiMacFilter of the file …

Mar 20, 2024
CVE-2024-2710
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by this vulnerability is the function setSchedWifi of the file …

Mar 20, 2024
CVE-2024-2709
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation …

Mar 20, 2024
CVE-2024-2708
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of …

Mar 20, 2024
CVE-2024-23821
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23819
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23818
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23643
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23642
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2023-45177
5.3 MEDIUM

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the …

Mar 20, 2024
CVE-2024-2707
6.3 MEDIUM

A vulnerability has been found in Tenda AC10U 15.03.06.49 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 20, 2024
CVE-2024-2706
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of …

Mar 20, 2024
CVE-2024-2705
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Affected by this issue is the function formSetQosBand of the file …

Mar 20, 2024
CVE-2024-2631
4.3 MEDIUM

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Mar 20, 2024
CVE-2024-2630
6.5 MEDIUM

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Mar 20, 2024
CVE-2024-2629
4.3 MEDIUM

Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

Mar 20, 2024
CVE-2024-2628
4.3 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: …

Mar 20, 2024
CVE-2024-2627
8.8 HIGH

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-2626
6.5 MEDIUM

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a …

Mar 20, 2024
CVE-2024-2625
8.8 HIGH

Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-1992

Rejected reason: Rejected as duplicate of CVE-2024-2306

Mar 20, 2024
CVE-2024-2704
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulnerability is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation …

Mar 20, 2024
CVE-2024-2703
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the …

Mar 20, 2024
CVE-2024-23640
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2024-23634
6.0 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists …

Mar 20, 2024
CVE-2023-51445
4.8 MEDIUM

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A stored cross-site scripting (XSS) vulnerability …

Mar 20, 2024
CVE-2023-50967
7.5 HIGH

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Mar 20, 2024
CVE-2024-2291
4.3 MEDIUM

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user …

Mar 20, 2024
CVE-2024-29419
5.4 MEDIUM

There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.

Mar 20, 2024
CVE-2024-28735
8.1 HIGH

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the …

Mar 20, 2024
CVE-2023-51444
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists …

Mar 20, 2024
CVE-2023-41877
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions …

Mar 20, 2024
CVE-2023-41038
7.5 HIGH

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific …

Mar 20, 2024
CVE-2024-28396
7.5 HIGH

An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

Mar 20, 2024
CVE-2024-28395
9.8 CRITICAL

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

Mar 20, 2024
CVE-2024-28392
9.8 CRITICAL

SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

Mar 20, 2024
CVE-2023-35888
5.9 MEDIUM

IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. …

Mar 20, 2024
CVE-2024-1856
8.5 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-1811
9.8 CRITICAL

A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited.

Mar 20, 2024
CVE-2024-1801
7.7 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-1800
9.9 CRITICAL

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

Mar 20, 2024
CVE-2024-2721
8.2 HIGH

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through …

Mar 20, 2024
CVE-2023-52229
6.5 MEDIUM

Missing Authorization vulnerability in Save as PDF plugin by Pdfcrowd Word Replacer Pro.This issue affects Word Replacer Pro: from n/a through 1.0.

Mar 20, 2024
CVE-2023-46841
6.5 MEDIUM

Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to …

Mar 20, 2024
CVE-2023-46840
4.1 MEDIUM

Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.