CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28823
6.1 MEDIUM

Amazon AWS aws-js-s3-explorer (aka AWS JavaScript S3 Explorer) 1.0.0 allows XSS via a crafted S3 bucket name to index.html.

Mar 11, 2024
CVE-2024-28816
7.1 HIGH

Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.

Mar 11, 2024
CVE-2024-2184
9.8 CRITICAL

Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the …

Mar 11, 2024
CVE-2024-2365
1.6 LOW

A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of …

Mar 11, 2024
CVE-2024-2364
1.8 LOW

A vulnerability classified as problematic has been found in Musicshelf 1.0/1.1 on Android. Affected is an unknown function of the file androidmanifest.xml of the component …

Mar 10, 2024
CVE-2024-2363
5.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. This vulnerability affects unknown code …

Mar 10, 2024
CVE-2024-2314
2.8 LOW

If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force …

Mar 10, 2024
CVE-2024-2313
2.8 LOW

If kernel headers need to be extracted, bpftrace will attempt to load them from a temporary directory. An unprivileged attacker could use this to force …

Mar 10, 2024
CVE-2024-2355
3.7 LOW

A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /secret_coder.sql. …

Mar 10, 2024
CVE-2024-2354
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of …

Mar 10, 2024
CVE-2024-2353
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Totolink X6000R 9.4.0cu.852_20230719. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of …

Mar 10, 2024
CVE-2024-28757
7.5 HIGH

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Mar 10, 2024
CVE-2024-2352
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the …

Mar 10, 2024
CVE-2024-2351
6.3 MEDIUM

A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of …

Mar 9, 2024
CVE-2024-27698

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Mar 9, 2024
CVE-2024-2333
6.3 MEDIUM

A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation …

Mar 9, 2024
CVE-2024-2332
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Mar 9, 2024
CVE-2024-2331
6.3 MEDIUM

A vulnerability was found in SourceCodester Tourist Reservation System 1.0. It has been declared as critical. This vulnerability affects the function ad_writedata of the file …

Mar 9, 2024
CVE-2024-1870
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callActivateLicenseEndpoint function in …

Mar 9, 2024
CVE-2024-2330
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file …

Mar 9, 2024
CVE-2024-2329
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the …

Mar 9, 2024
CVE-2024-25501
8.8 HIGH

An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.

Mar 9, 2024
CVE-2024-28089
5.2 MEDIUM

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panel) to conduct a DOM-based stored …

Mar 9, 2024
CVE-2024-1767
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to …

Mar 9, 2024
CVE-2024-1320
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up …

Mar 9, 2024
CVE-2024-1125
5.4 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-1124
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the …

Mar 9, 2024
CVE-2024-1123
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-25951
8.0 HIGH

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

Mar 9, 2024
CVE-2023-46427
9.8 CRITICAL

An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information …

Mar 9, 2024
CVE-2023-46426
8.8 HIGH

Heap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) via gf_fwrite component …

Mar 9, 2024
CVE-2023-50015
8.8 HIGH

An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity …

Mar 9, 2024
CVE-2023-49341
7.5 HIGH

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm …

Mar 9, 2024
CVE-2023-49340
9.8 CRITICAL

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control …

Mar 9, 2024
CVE-2024-28184
7.4 HIGH

WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a …

Mar 9, 2024
CVE-2024-28180
4.3 MEDIUM

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed …

Mar 9, 2024
CVE-2024-28176
4.9 MEDIUM

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), …

Mar 9, 2024
CVE-2024-28122
6.8 MEDIUM

JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause …

Mar 9, 2024
CVE-2024-28754
7.5 HIGH

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.

Mar 9, 2024
CVE-2024-28753
6.5 MEDIUM

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.

Mar 9, 2024
CVE-2023-32264
5.8 MEDIUM

CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.

Mar 8, 2024
CVE-2024-2339
8.0 HIGH

PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user can define a masking function …

Mar 8, 2024
CVE-2024-2338
8.0 HIGH

PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to superuser when dynamic masking is enabled. …

Mar 8, 2024
CVE-2022-43855
6.2 MEDIUM

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity …

Mar 8, 2024
CVE-2024-21901
4.7 MEDIUM

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. …

Mar 8, 2024
CVE-2024-21900
4.3 MEDIUM

An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via …

Mar 8, 2024
CVE-2024-21899
9.8 CRITICAL

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security …

Mar 8, 2024
CVE-2023-47221
5.5 MEDIUM

A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected …

Mar 8, 2024
CVE-2023-34980
5.9 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Mar 8, 2024
CVE-2023-32969
4.9 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious …

Mar 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.