CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24276
9.6 CRITICAL

Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload …

Mar 5, 2024
CVE-2024-24275
9.6 CRITICAL

Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to …

Mar 5, 2024
CVE-2023-48644
6.1 MEDIUM

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance …

Mar 5, 2024
CVE-2023-45290
6.5 MEDIUM

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form …

Mar 5, 2024
CVE-2023-45289
4.3 MEDIUM

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not …

Mar 5, 2024
CVE-2024-1901
4.3 MEDIUM

Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make …

Mar 5, 2024
CVE-2024-1900
5.5 MEDIUM

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay …

Mar 5, 2024
CVE-2024-1898
4.3 MEDIUM

Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an …

Mar 5, 2024
CVE-2024-1764
7.6 HIGH

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after …

Mar 5, 2024
CVE-2024-2179
2.2 LOW

Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of …

Mar 5, 2024
CVE-2024-25858
8.4 HIGH

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users …

Mar 5, 2024
CVE-2024-25616
3.7 LOW

Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which …

Mar 5, 2024
CVE-2024-25615
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in …

Mar 5, 2024
CVE-2024-25614
5.5 MEDIUM

There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary …

Mar 5, 2024
CVE-2024-25613
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-25612
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-25611
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-1356
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-2056
9.8 CRITICAL

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service …

Mar 5, 2024
CVE-2024-2055
9.8 CRITICAL

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication …

Mar 5, 2024
CVE-2024-23296
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-23256
3.3 LOW

A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be …

Mar 5, 2024
CVE-2024-23243
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app …

Mar 5, 2024
CVE-2024-23225
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2023-26282
4.2 MEDIUM

IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or …

Mar 5, 2024
CVE-2023-25681
5.3 MEDIUM

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and …

Mar 5, 2024
CVE-2022-22399
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Mar 5, 2024
CVE-2024-22255
7.1 HIGH

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine …

Mar 5, 2024
CVE-2024-22254
7.9 HIGH

VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape …

Mar 5, 2024
CVE-2024-22253
9.3 CRITICAL

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine …

Mar 5, 2024
CVE-2024-22252
9.3 CRITICAL

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine …

Mar 5, 2024
CVE-2024-27931
5.8 MEDIUM

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside …

Mar 5, 2024
CVE-2024-27929
7.1 HIGH

ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when …

Mar 5, 2024
CVE-2024-27565
9.8 CRITICAL

A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.

Mar 5, 2024
CVE-2024-27564
5.8 MEDIUM

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from …

Mar 5, 2024
CVE-2024-27563
5.3 MEDIUM

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2024-27561
8.1 HIGH

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2024-24098
7.8 HIGH

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

Mar 5, 2024
CVE-2022-46088
6.1 MEDIUM

Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

Mar 5, 2024
CVE-2024-27627
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the …

Mar 5, 2024
CVE-2024-27625
4.8 MEDIUM

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, …

Mar 5, 2024
CVE-2024-27623
5.9 MEDIUM

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

Mar 5, 2024
CVE-2024-27622
7.2 HIGH

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises …

Mar 5, 2024
CVE-2024-2188
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a …

Mar 5, 2024
CVE-2023-7103
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass.This issue affects UFace 5: through 12022024.

Mar 5, 2024
CVE-2023-5457
7.5 HIGH

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set …

Mar 5, 2024
CVE-2023-45600
5.6 MEDIUM

A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. …

Mar 5, 2024
CVE-2023-45599
5.5 MEDIUM

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker …

Mar 5, 2024
CVE-2023-45598
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. …

Mar 5, 2024
CVE-2023-45597
5.9 MEDIUM

A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows …

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.