CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32633
6.7 MEDIUM

Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local …

Mar 14, 2024
CVE-2023-32282
7.2 HIGH

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Mar 14, 2024
CVE-2023-28746
6.5 MEDIUM

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable …

Mar 14, 2024
CVE-2023-28389
6.7 MEDIUM

Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local …

Mar 14, 2024
CVE-2023-27502
3.3 LOW

Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2316.5.1.2 may allow an authenticated user to potentially enable …

Mar 14, 2024
CVE-2023-22655
6.1 MEDIUM

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to …

Mar 14, 2024
CVE-2024-25139
10.0 CRITICAL

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After …

Mar 14, 2024
CVE-2023-50168
7.7 HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Mar 14, 2024
CVE-2024-28323
6.5 MEDIUM

The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The …

Mar 14, 2024
CVE-2024-25156
6.5 MEDIUM

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web …

Mar 14, 2024
CVE-2024-28418
6.5 MEDIUM

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

Mar 14, 2024
CVE-2024-28417
6.3 MEDIUM

Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.

Mar 14, 2024
CVE-2024-28383
9.8 CRITICAL

Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.

Mar 14, 2024
CVE-2024-1623
7.7 HIGH

Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without …

Mar 14, 2024
CVE-2024-28746
8.1 HIGH

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc …

Mar 14, 2024
CVE-2024-27986
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor Addons by Livemesh allows Stored XSS.This issue affects Elementor Addons by …

Mar 14, 2024
CVE-2024-0313
5.5 MEDIUM

A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately …

Mar 14, 2024
CVE-2024-0312
5.5 MEDIUM

A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

Mar 14, 2024
CVE-2024-0311
5.5 MEDIUM

A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

Mar 14, 2024
CVE-2024-28391
9.8 CRITICAL

SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the …

Mar 14, 2024
CVE-2024-28390
9.8 CRITICAL

An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access …

Mar 14, 2024
CVE-2024-22398
4.9 MEDIUM

An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative …

Mar 14, 2024
CVE-2024-22397
8.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user …

Mar 14, 2024
CVE-2024-22396
5.3 MEDIUM

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially …

Mar 14, 2024
CVE-2024-1884
6.5 MEDIUM

This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an attacker to induce the server-side application to make …

Mar 14, 2024
CVE-2024-1883
6.3 MEDIUM

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL …

Mar 14, 2024
CVE-2024-1882
7.2 HIGH

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting …

Mar 14, 2024
CVE-2024-28388
9.8 CRITICAL

SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the …

Mar 14, 2024
CVE-2024-25653
4.3 MEDIUM

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system …

Mar 14, 2024
CVE-2024-25652
7.6 HIGH

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN …

Mar 14, 2024
CVE-2024-25651
5.3 MEDIUM

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user …

Mar 14, 2024
CVE-2024-25649
6.7 MEDIUM

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data …

Mar 14, 2024
CVE-2024-1654
7.2 HIGH

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of …

Mar 14, 2024
CVE-2024-1223
4.8 MEDIUM

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid …

Mar 14, 2024
CVE-2024-1222
8.6 HIGH

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a …

Mar 14, 2024
CVE-2024-1221
3.1 LOW

This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker …

Mar 14, 2024
CVE-2024-25650
5.9 MEDIUM

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to …

Mar 14, 2024
CVE-2024-25228
8.8 HIGH

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

Mar 14, 2024
CVE-2024-28251
5.6 MEDIUM

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. …

Mar 14, 2024
CVE-2024-2242
6.1 MEDIUM

The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and including, 5.9 …

Mar 13, 2024
CVE-2024-2079
6.4 MEDIUM

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'per_line_mobile' shortcode in all versions up …

Mar 13, 2024
CVE-2024-27703
5.4 MEDIUM

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

Mar 13, 2024
CVE-2023-38536
6.4 MEDIUM

HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.

Mar 13, 2024
CVE-2023-38535
4.7 MEDIUM

Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.

Mar 13, 2024
CVE-2023-38534
8.6 HIGH

Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.

Mar 13, 2024
CVE-2020-11862
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged …

Mar 13, 2024
CVE-2024-28662
5.4 MEDIUM

A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.

Mar 13, 2024
CVE-2024-28193
6.5 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the settings, which can …

Mar 13, 2024
CVE-2024-28192
5.3 MEDIUM

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public access token processing logic. …

Mar 13, 2024
CVE-2024-28175
9.0 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.