CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2319
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality …

Mar 8, 2024
CVE-2024-2318
4.3 MEDIUM

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of …

Mar 8, 2024
CVE-2024-2317
3.8 LOW

A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of the file /prescription/prescription/delete/ …

Mar 8, 2024
CVE-2024-2316
4.3 MEDIUM

A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnerability affects unknown code of the file /billing/bill/edit/ …

Mar 8, 2024
CVE-2023-52496

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 8, 2024
CVE-2024-2298
4.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in …

Mar 8, 2024
CVE-2024-1851
6.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in …

Mar 8, 2024
CVE-2024-27613
7.3 HIGH

Numbas editor before 7.3 mishandles reading of themes and extensions.

Mar 8, 2024
CVE-2024-27612
6.2 MEDIUM

Numbas editor before 7.3 mishandles editing of themes and extensions.

Mar 8, 2024
CVE-2024-1987
6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 …

Mar 8, 2024
CVE-2024-2285
3.5 LOW

A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. Affected by this issue is some unknown functionality of the file …

Mar 8, 2024
CVE-2024-2284
3.5 LOW

A vulnerability classified as problematic was found in boyiddha Automated-Mess-Management-System 1.0. Affected by this vulnerability is an unknown functionality of the file /member/chat.php of the …

Mar 8, 2024
CVE-2024-2283
6.3 MEDIUM

A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the …

Mar 8, 2024
CVE-2024-2282
7.3 HIGH

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of …

Mar 8, 2024
CVE-2024-2281
6.3 MEDIUM

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the …

Mar 8, 2024
CVE-2024-2277
4.3 MEDIUM

A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Mar 8, 2024
CVE-2024-26313
7.3 HIGH

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this …

Mar 8, 2024
CVE-2024-26309
5.3 MEDIUM

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via …

Mar 8, 2024
CVE-2024-25849
9.8 CRITICAL

In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

Mar 8, 2024
CVE-2024-25848
5.9 MEDIUM

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

Mar 8, 2024
CVE-2024-25845
9.8 CRITICAL

In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.

Mar 8, 2024
CVE-2024-23297
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may …

Mar 8, 2024
CVE-2024-23295
5.5 MEDIUM

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able …

Mar 8, 2024
CVE-2024-23294
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.4. Processing malicious input may lead to code execution.

Mar 8, 2024
CVE-2024-23293
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23292
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be …

Mar 8, 2024
CVE-2024-23291
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma …

Mar 8, 2024
CVE-2024-23290
5.5 MEDIUM

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23289
3.3 LOW

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, …

Mar 8, 2024
CVE-2024-23288
7.8 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS …

Mar 8, 2024
CVE-2024-23287
5.5 MEDIUM

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS …

Mar 8, 2024
CVE-2024-23286
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, …

Mar 8, 2024
CVE-2024-23285
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks …

Mar 8, 2024
CVE-2024-23284
6.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS …

Mar 8, 2024
CVE-2024-23283
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey …

Mar 8, 2024
CVE-2024-23281
5.5 MEDIUM

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user …

Mar 8, 2024
CVE-2024-23280
6.5 MEDIUM

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, …

Mar 8, 2024
CVE-2024-23279
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be …

Mar 8, 2024
CVE-2024-23278
8.6 HIGH

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, …

Mar 8, 2024
CVE-2024-23277
5.9 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged …

Mar 8, 2024
CVE-2024-23276
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may …

Mar 8, 2024
CVE-2024-23275
4.7 MEDIUM

A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may …

Mar 8, 2024
CVE-2024-23274
7.8 HIGH

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app …

Mar 8, 2024
CVE-2024-23273
4.3 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing …

Mar 8, 2024
CVE-2024-23272
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may …

Mar 8, 2024
CVE-2024-23270
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS …

Mar 8, 2024
CVE-2024-23269
5.5 MEDIUM

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS …

Mar 8, 2024
CVE-2024-23268
7.8 HIGH

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app …

Mar 8, 2024
CVE-2024-23267
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be …

Mar 8, 2024
CVE-2024-23266
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be …

Mar 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.