CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0055
6.5 MEDIUM

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs mediaclip.cgi and playclip.cgi was vulnerable for file globbing which …

Mar 19, 2024
CVE-2024-0054
6.5 MEDIUM

Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX APIs local_list.cgi, create_overlay.cgi and irissetup.cgi was vulnerable for file globbing …

Mar 19, 2024
CVE-2024-28447
6.5 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_ipaddr parameters at /apply.cgi.

Mar 19, 2024
CVE-2024-28446
5.7 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-mini1 v1.2.9 was discovered to contain a buffer overflow via lan_netmask parameter at /apply.cgi.

Mar 19, 2024
CVE-2024-26369
7.5 HIGH

An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.

Mar 19, 2024
CVE-2024-22025
6.5 MEDIUM

A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve …

Mar 19, 2024
CVE-2024-22017
7.3 HIGH

setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows the process to perform privileged operations despite presumably …

Mar 19, 2024
CVE-2024-21504
6.1 MEDIUM

Versions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url] for a property. An …

Mar 19, 2024
CVE-2024-21503
5.3 MEDIUM

Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An …

Mar 19, 2024
CVE-2024-2622
6.3 MEDIUM

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318. It has been classified as critical. This affects an unknown …

Mar 19, 2024
CVE-2024-2621
6.3 MEDIUM

A vulnerability was found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this issue is some …

Mar 19, 2024
CVE-2024-2620
6.3 MEDIUM

A vulnerability has been found in Fujian Kelixin Communication Command and Dispatch Platform up to 20240318 and classified as critical. Affected by this vulnerability is …

Mar 19, 2024
CVE-2023-40280
7.5 HIGH

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to …

Mar 19, 2024
CVE-2023-40277
6.1 MEDIUM

An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter.

Mar 19, 2024
CVE-2023-40276
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.

Mar 19, 2024
CVE-2023-40275
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

Mar 19, 2024
CVE-2024-28865
7.5 HIGH

django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe …

Mar 18, 2024
CVE-2024-28864
2.6 LOW

SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerability in SecureProps version 1.2.0 and 1.2.1 …

Mar 18, 2024
CVE-2024-28855
8.1 HIGH

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Due to a improper use of the `text/template` instead of the …

Mar 18, 2024
CVE-2024-28250
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.14.0 and prior to versions 1.14.8 and 1.15.2, In Cilium …

Mar 18, 2024
CVE-2024-28249
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.13.13, 1.14.8, and 1.15.2, in Cilium clusters with IPsec enabled …

Mar 18, 2024
CVE-2024-28248
7.2 HIGH

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 and prior to versions 1.13.13, 1.14.8, and 1.15.2, Cilium's …

Mar 18, 2024
CVE-2024-28237
4.0 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to …

Mar 18, 2024
CVE-2024-24578
10.0 CRITICAL

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, …

Mar 18, 2024
CVE-2024-2604
6.3 MEDIUM

A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update-file.php. …

Mar 18, 2024
CVE-2024-23333
7.9 HIGH

LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log …

Mar 18, 2024
CVE-2024-22412
2.4 LOW

ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. …

Mar 18, 2024
CVE-2024-25657
5.4 MEDIUM

An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to …

Mar 18, 2024
CVE-2024-25656
5.9 MEDIUM

Improper input validation in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS can result in unauthenticated CPE (Customer Premises Equipment) devices storing arbitrarily large amounts of data …

Mar 18, 2024
CVE-2024-25655
6.5 MEDIUM

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) …

Mar 18, 2024
CVE-2024-25654
5.5 MEDIUM

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP application server) to access credentials …

Mar 18, 2024
CVE-2024-21662
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate …

Mar 18, 2024
CVE-2024-21661
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a critical flaw …

Mar 18, 2024
CVE-2024-0973
6.1 MEDIUM

The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users …

Mar 18, 2024
CVE-2024-0951
4.8 MEDIUM

The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege …

Mar 18, 2024
CVE-2024-0858
8.8 HIGH

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Mar 18, 2024
CVE-2024-0820
5.4 MEDIUM

The Jobs for WordPress plugin before 2.7.4 does not sanitise and escape some parameters, which could allow users with a role as low as contributor …

Mar 18, 2024
CVE-2024-0780
8.8 HIGH

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when resetting its database, allowing any authenticated users, such …

Mar 18, 2024
CVE-2024-0779
8.8 HIGH

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing …

Mar 18, 2024
CVE-2024-0719
5.4 MEDIUM

The Tabs Shortcode and Widget WordPress plugin through 1.17 does not validate and escape some of its shortcode attributes before outputting them back in a …

Mar 18, 2024
CVE-2024-0711
6.1 MEDIUM

The Buttons Shortcode and Widget WordPress plugin through 1.16 does not validate and escape some of its shortcode attributes before outputting them back in a …

Mar 18, 2024
CVE-2024-0365
6.5 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Mar 18, 2024
CVE-2023-7236
4.7 MEDIUM

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated …

Mar 18, 2024
CVE-2023-7085
5.4 MEDIUM

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as …

Mar 18, 2024
CVE-2023-6821
6.5 MEDIUM

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs …

Mar 18, 2024
CVE-2023-41334
8.4 HIGH

Astropy is a project for astronomy in Python that fosters interoperability between Python astronomy packages. Version 5.3.2 of the Astropy core package is vulnerable to …

Mar 18, 2024
CVE-2024-26125
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Mar 18, 2024
CVE-2024-26124
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Mar 18, 2024
CVE-2024-26120
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Mar 18, 2024
CVE-2024-26119
5.3 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An attacker could …

Mar 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.