CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-4629
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, …

Mar 12, 2024
CVE-2023-4628
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, …

Mar 12, 2024
CVE-2023-4627
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up …

Mar 12, 2024
CVE-2023-4626
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up …

Mar 12, 2024
CVE-2024-2371
6.2 MEDIUM

Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer data, allowing an attacker to intercept …

Mar 12, 2024
CVE-2024-27279
6.5 MEDIUM

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 …

Mar 12, 2024
CVE-2024-26288
8.7 HIGH

An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

Mar 12, 2024
CVE-2024-26005
4.8 MEDIUM

An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.

Mar 12, 2024
CVE-2024-26004
7.5 HIGH

An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

Mar 12, 2024
CVE-2024-26003
7.5 HIGH

An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality.

Mar 12, 2024
CVE-2024-26002
7.8 HIGH

An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific …

Mar 12, 2024
CVE-2024-26001
7.4 HIGH

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not …

Mar 12, 2024
CVE-2024-26000
5.9 MEDIUM

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not …

Mar 12, 2024
CVE-2024-25999
8.4 HIGH

An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.

Mar 12, 2024
CVE-2024-25998
7.3 HIGH

An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

Mar 12, 2024
CVE-2024-25997
5.3 MEDIUM

An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

Mar 12, 2024
CVE-2024-25996
5.3 MEDIUM

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

Mar 12, 2024
CVE-2024-25995
9.8 CRITICAL

An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.

Mar 12, 2024
CVE-2024-25994
5.3 MEDIUM

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

Mar 12, 2024
CVE-2024-1328
6.4 MEDIUM

The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to …

Mar 12, 2024
CVE-2024-0906
5.3 MEDIUM

The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This …

Mar 12, 2024
CVE-2024-27121
7.2 HIGH

Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be …

Mar 12, 2024
CVE-2024-25325
7.1 HIGH

SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in …

Mar 12, 2024
CVE-2024-24964
6.3 MEDIUM

Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an …

Mar 12, 2024
CVE-2024-21805
7.8 HIGH

Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an …

Mar 12, 2024
CVE-2024-21584
6.1 MEDIUM

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and …

Mar 12, 2024
CVE-2023-49453
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component …

Mar 12, 2024
CVE-2024-25331
9.3 CRITICAL

DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based …

Mar 12, 2024
CVE-2024-26521
4.8 MEDIUM

HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a …

Mar 12, 2024
CVE-2023-6814
5.6 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: …

Mar 12, 2024
CVE-2024-28163
5.3 MEDIUM

Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be …

Mar 12, 2024
CVE-2024-27902
5.4 MEDIUM

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site …

Mar 12, 2024
CVE-2024-27900
4.3 MEDIUM

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job …

Mar 12, 2024
CVE-2024-25645
5.3 MEDIUM

Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on …

Mar 12, 2024
CVE-2024-25644
5.3 MEDIUM

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality …

Mar 12, 2024
CVE-2024-22133
4.6 MEDIUM

SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead …

Mar 12, 2024
CVE-2024-22127
9.1 CRITICAL

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads …

Mar 12, 2024
CVE-2023-49785
9.1 CRITICAL

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery …

Mar 12, 2024
CVE-2024-28199
7.1 HIGH

phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via …

Mar 11, 2024
CVE-2024-28120
6.5 MEDIUM

codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when …

Mar 11, 2024
CVE-2024-27938
5.3 MEDIUM

Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be …

Mar 11, 2024
CVE-2024-27297
6.3 MEDIUM

Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors to files in the Nix …

Mar 11, 2024
CVE-2024-25854
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting …

Mar 11, 2024
CVE-2024-25114
2.6 LOW

Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in …

Mar 11, 2024
CVE-2024-1645
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportRegistrations function in all …

Mar 11, 2024
CVE-2024-1400
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in …

Mar 11, 2024
CVE-2022-46070
7.5 HIGH

GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

Mar 11, 2024
CVE-2024-2357
6.5 MEDIUM

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys …

Mar 11, 2024
CVE-2024-28198
4.6 MEDIUM

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it …

Mar 11, 2024
CVE-2024-28197
7.5 HIGH

Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie …

Mar 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.