CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2015-10123
8.8 HIGH

An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page …

Mar 13, 2024
CVE-2024-28623
6.1 MEDIUM

RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.

Mar 13, 2024
CVE-2024-26529
7.5 HIGH

An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.

Mar 13, 2024
CVE-2024-27440
4.8 MEDIUM

The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3.14 don't properly verify server …

Mar 13, 2024
CVE-2024-2400
8.8 HIGH

Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Mar 13, 2024
CVE-2024-2413
9.8 CRITICAL

Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and …

Mar 13, 2024
CVE-2024-2412
5.3 MEDIUM

The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowing remote attackers to complete user registration on …

Mar 13, 2024
CVE-2015-10130
5.3 MEDIUM

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or …

Mar 13, 2024
CVE-2024-1582
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions …

Mar 13, 2024
CVE-2023-4839
4.4 MEDIUM

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient …

Mar 13, 2024
CVE-2024-1421
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘border_type’ attribute of the Post Carousel …

Mar 12, 2024
CVE-2024-1397
6.4 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up …

Mar 12, 2024
CVE-2023-7072
7.5 HIGH

The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 …

Mar 12, 2024
CVE-2024-2395
7.3 HIGH

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to …

Mar 12, 2024
CVE-2024-2107
5.8 MEDIUM

The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes …

Mar 12, 2024
CVE-2024-24101
9.8 CRITICAL

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

Mar 12, 2024
CVE-2024-0386
7.2 HIGH

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due …

Mar 12, 2024
CVE-2023-43279
6.5 MEDIUM

Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.

Mar 12, 2024
CVE-2024-2406
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The …

Mar 12, 2024
CVE-2024-28239
5.4 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as …

Mar 12, 2024
CVE-2024-28238
2.3 LOW

Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. …

Mar 12, 2024
CVE-2024-28236
7.7 HIGH

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields …

Mar 12, 2024
CVE-2024-27305
5.3 MEDIUM

aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability …

Mar 12, 2024
CVE-2024-24097
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

Mar 12, 2024
CVE-2024-24093
9.8 CRITICAL

SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

Mar 12, 2024
CVE-2024-24092
7.8 HIGH

SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

Mar 12, 2024
CVE-2024-23300
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected …

Mar 12, 2024
CVE-2023-43292
6.1 MEDIUM

Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted …

Mar 12, 2024
CVE-2023-42308
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" …

Mar 12, 2024
CVE-2023-42307
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

Mar 12, 2024
CVE-2024-2130
6.4 MEDIUM

The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versions up to, and including, 1.2.7 due …

Mar 12, 2024
CVE-2024-2031
6.4 MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and …

Mar 12, 2024
CVE-2024-28186
7.1 HIGH

FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes …

Mar 12, 2024
CVE-2024-28121
8.8 HIGH

stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. …

Mar 12, 2024
CVE-2024-28114
8.1 HIGH

Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager …

Mar 12, 2024
CVE-2024-28113
3.5 LOW

Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arbitrary page using a crafted …

Mar 12, 2024
CVE-2024-28112
6.1 MEDIUM

Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored Cross-Site Scripting (XSS) attack in the …

Mar 12, 2024
CVE-2023-5410
8.2 HIGH

A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation …

Mar 12, 2024
CVE-2023-30968
6.8 MEDIUM

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass …

Mar 12, 2024
CVE-2024-28098
6.4 MEDIUM

The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings. These management operations …

Mar 12, 2024
CVE-2024-27894
8.5 HIGH

The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported …

Mar 12, 2024
CVE-2024-27317
8.4 HIGH

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. …

Mar 12, 2024
CVE-2024-27135
8.5 HIGH

Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of …

Mar 12, 2024
CVE-2022-34321
8.2 HIGH

Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about …

Mar 12, 2024
CVE-2024-1765
5.9 MEDIUM

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server …

Mar 12, 2024
CVE-2024-1410
3.7 LOW

Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each …

Mar 12, 2024
CVE-2024-1138
8.8 HIGH

The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access …

Mar 12, 2024
CVE-2024-1137
4.3 MEDIUM

The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to …

Mar 12, 2024
CVE-2024-2182
6.5 MEDIUM

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can …

Mar 12, 2024
CVE-2024-28340
7.5 HIGH

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without …

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.