CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-46091
4.7 MEDIUM

Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 7, 2024
CVE-2024-28222
9.8 CRITICAL

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and …

Mar 7, 2024
CVE-2024-1506
6.4 MEDIUM

The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tags' attribute of the Fiestar widget in …

Mar 7, 2024
CVE-2024-1419
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attribute of the Header Meta Content widget …

Mar 7, 2024
CVE-2024-1720
4.7 MEDIUM

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 7, 2024
CVE-2024-1500
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo Widget in all versions up to, and …

Mar 7, 2024
CVE-2024-1377
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_tag’ attribute of the Author Meta widget in all …

Mar 7, 2024
CVE-2024-1366
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_tag’ attribute of the Archive Title widget in all …

Mar 7, 2024
CVE-2024-28216
5.4 MEDIUM

nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of …

Mar 7, 2024
CVE-2024-28215
7.5 HIGH

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information …

Mar 7, 2024
CVE-2024-28214
2.7 LOW

nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.

Mar 7, 2024
CVE-2024-28213
9.8 CRITICAL

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects …

Mar 7, 2024
CVE-2024-28212
9.8 CRITICAL

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Mar 7, 2024
CVE-2024-28211
9.8 CRITICAL

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote …

Mar 7, 2024
CVE-2024-1761
6.4 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 …

Mar 7, 2024
CVE-2023-51395
8.8 HIGH

The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range …

Mar 7, 2024
CVE-2024-28097
7.3 HIGH

Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28096
7.3 HIGH

Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28095
7.3 HIGH

News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28094
8.8 HIGH

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

Mar 7, 2024
CVE-2024-0815
8.8 HIGH

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2024-1460
5.6 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-1443
4.4 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-24389
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 7, 2024
CVE-2024-0817
7.8 HIGH

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2022-46089
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 7, 2024
CVE-2024-26566
8.2 HIGH

An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.

Mar 7, 2024
CVE-2024-24375
7.5 HIGH

SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.

Mar 7, 2024
CVE-2024-22857
9.8 CRITICAL

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) …

Mar 7, 2024
CVE-2024-1299
6.5 MEDIUM

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user …

Mar 7, 2024
CVE-2024-0199
7.7 HIGH

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker …

Mar 7, 2024
CVE-2023-51786
9.1 CRITICAL

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access …

Mar 7, 2024
CVE-2023-51281
5.4 MEDIUM

Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and …

Mar 7, 2024
CVE-2023-49989
9.8 CRITICAL

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

Mar 7, 2024
CVE-2023-49988
7.5 HIGH

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.

Mar 7, 2024
CVE-2023-49987
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2023-49986
4.7 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2023-47415
7.5 HIGH

Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

Mar 7, 2024
CVE-2024-2236
5.9 MEDIUM

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead …

Mar 6, 2024
CVE-2024-28111
6.5 MEDIUM

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these …

Mar 6, 2024
CVE-2024-28110
7.5 HIGH

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with …

Mar 6, 2024
CVE-2024-27917
7.5 HIGH

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the …

Mar 6, 2024
CVE-2024-27915
6.8 MEDIUM

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of …

Mar 6, 2024
CVE-2024-27308
7.5 HIGH

Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to …

Mar 6, 2024
CVE-2024-27307
9.8 CRITICAL

JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the …

Mar 6, 2024
CVE-2023-48703
7.5 HIGH

RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` …

Mar 6, 2024
CVE-2024-2176
8.8 HIGH

Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 6, 2024
CVE-2024-2174
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 6, 2024
CVE-2024-2173
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via …

Mar 6, 2024
CVE-2024-27304
9.8 CRITICAL

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to …

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.