CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2266
3.5 LOW

A vulnerability has been found in keerti1924 Secret-Coder-PHP-Project 1.0 and classified as problematic. This vulnerability affects unknown code of the file /login.php of the component …

Mar 7, 2024
CVE-2024-2265
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads …

Mar 7, 2024
CVE-2024-2264
7.3 HIGH

A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file …

Mar 7, 2024
CVE-2024-2044
9.9 CRITICAL

pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, …

Mar 7, 2024
CVE-2024-28115
8.8 HIGH

FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming …

Mar 7, 2024
CVE-2024-27707
4.3 MEDIUM

Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.

Mar 7, 2024
CVE-2024-26492
6.3 MEDIUM

An issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted POST …

Mar 7, 2024
CVE-2024-26167
4.3 MEDIUM

Microsoft Edge for Android Spoofing Vulnerability

Mar 7, 2024
CVE-2024-24035
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.

Mar 7, 2024
CVE-2024-1986
8.8 HIGH

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in …

Mar 7, 2024
CVE-2024-1802
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 7, 2024
CVE-2023-46172
5.6 MEDIUM

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions for authorized user. IBM X-Force ID: 269409.

Mar 7, 2024
CVE-2023-46171
4.3 MEDIUM

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to view sensitive log information after enumerating filenames. IBM X-Force ID: …

Mar 7, 2024
CVE-2023-46170
6.5 MEDIUM

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily read files after enumerating file names.

Mar 7, 2024
CVE-2023-46169
6.5 MEDIUM

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X-Force ID: 269406.

Mar 7, 2024
CVE-2024-2128
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 7, 2024
CVE-2024-2127
6.4 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom attributes in all versions …

Mar 7, 2024
CVE-2024-1725
6.5 MEDIUM

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access …

Mar 7, 2024
CVE-2024-0203
8.8 HIGH

The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation …

Mar 7, 2024
CVE-2024-1773
8.8 HIGH

The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 …

Mar 7, 2024
CVE-2024-22752
8.1 HIGH

Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation …

Mar 7, 2024
CVE-2024-1442
6.0 MEDIUM

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing …

Mar 7, 2024
CVE-2024-27733
7.7 HIGH

File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.

Mar 7, 2024
CVE-2024-1351
8.8 HIGH

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively …

Mar 7, 2024
CVE-2023-48725
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead …

Mar 7, 2024
CVE-2023-47691

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 7, 2024
CVE-2023-42661
7.2 HIGH

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when …

Mar 7, 2024
CVE-2023-42509
6.6 MEDIUM

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository …

Mar 7, 2024
CVE-2024-2245
5.4 MEDIUM

Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a JavaScript payload could be executed in the 'username' …

Mar 7, 2024
CVE-2024-2241
6.3 MEDIUM

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions

Mar 7, 2024
CVE-2024-0818
9.1 CRITICAL

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

Mar 7, 2024
CVE-2024-28230
6.5 MEDIUM

In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin permissions

Mar 7, 2024
CVE-2024-28229
6.5 MEDIUM

In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles

Mar 7, 2024
CVE-2024-28228
5.3 MEDIUM

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

Mar 7, 2024
CVE-2024-1170
8.2 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Mar 7, 2024
CVE-2024-1169
7.5 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Mar 7, 2024
CVE-2024-22256
4.3 MEDIUM

VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the …

Mar 7, 2024
CVE-2024-1931
7.5 HIGH

NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path …

Mar 7, 2024
CVE-2024-1534
6.4 MEDIUM

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 7.1.7 …

Mar 7, 2024
CVE-2024-2136
6.4 MEDIUM

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget in all versions up to, and …

Mar 7, 2024
CVE-2024-1382
8.8 HIGH

The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of …

Mar 7, 2024
CVE-2024-0917
9.8 CRITICAL

remote code execution in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2023-42662
9.3 CRITICAL

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could …

Mar 7, 2024
CVE-2023-41503
9.8 CRITICAL

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

Mar 7, 2024
CVE-2023-41015
5.5 MEDIUM

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.

Mar 7, 2024
CVE-2023-41014
9.8 CRITICAL

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

Mar 7, 2024
CVE-2023-33676
8.4 HIGH

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.

Mar 7, 2024
CVE-2022-46499
8.8 HIGH

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

Mar 7, 2024
CVE-2022-46498
2.7 LOW

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

Mar 7, 2024
CVE-2022-46497
8.1 HIGH

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.

Mar 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.