CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23492
5.7 MEDIUM

A weak encoding is used to transmit credentials for WS203VICM.

Mar 1, 2024
CVE-2024-22182
8.6 HIGH

A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM causing the system to restart, interrupting …

Mar 1, 2024
CVE-2024-21767
9.4 CRITICAL

A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.

Mar 1, 2024
CVE-2024-20328
5.3 MEDIUM

A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The …

Mar 1, 2024
CVE-2023-7244
9.8 CRITICAL

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function …

Mar 1, 2024
CVE-2023-7243
9.8 CRITICAL

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write while analyzing specific Ethercat datagrams. …

Mar 1, 2024
CVE-2023-7242
8.2 HIGH

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read during the process of analyzing …

Mar 1, 2024
CVE-2024-1174
8.2 HIGH

Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.0 SP 8, …

Mar 1, 2024
CVE-2024-2077
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file index.php. The …

Mar 1, 2024
CVE-2024-2076
5.3 MEDIUM

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-1453
7.8 HIGH

In Sante DICOM Viewer Pro versions 14.0.3 and prior, a user must open a malicious DICOM file, which could allow a local attacker to disclose …

Mar 1, 2024
CVE-2024-2075
3.5 LOW

A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Mar 1, 2024
CVE-2024-2074
6.3 MEDIUM

A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation …

Mar 1, 2024
CVE-2024-27298
10.0 CRITICAL

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The …

Mar 1, 2024
CVE-2024-2073
6.3 MEDIUM

A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Mar 1, 2024
CVE-2024-2072
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Flashcard Quiz App 1.0. This affects an unknown part of the file /endpoint/update-flashcard.php. The …

Mar 1, 2024
CVE-2024-2071
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affected by this issue is some unknown functionality of …

Mar 1, 2024
CVE-2024-27734
6.1 MEDIUM

A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fields …

Mar 1, 2024
CVE-2024-27692

Rejected reason: * REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-22939. Reason: This candidate is a duplicate of CVE-2024-22939. Notes: All CVE users …

Mar 1, 2024
CVE-2024-27689
8.8 HIGH

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.

Mar 1, 2024
CVE-2024-27559
6.3 MEDIUM

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

Mar 1, 2024
CVE-2024-27558
6.1 MEDIUM

Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.

Mar 1, 2024
CVE-2023-52558
7.5 HIGH

In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could …

Mar 1, 2024
CVE-2023-52557
7.5 HIGH

In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.

Mar 1, 2024
CVE-2023-52556
6.2 MEDIUM

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

Mar 1, 2024
CVE-2024-2070
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester FAQ Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-faq.php. …

Mar 1, 2024
CVE-2024-2069
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file /endpoint/delete-faq.php. The manipulation …

Mar 1, 2024
CVE-2024-2068
3.5 LOW

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Mar 1, 2024
CVE-2024-27499
6.5 MEDIUM

Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

Mar 1, 2024
CVE-2024-27296
5.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped …

Mar 1, 2024
CVE-2024-27295
8.2 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive …

Mar 1, 2024
CVE-2024-27140
5.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Archiva. This issue affects Apache Archiva: from …

Mar 1, 2024
CVE-2024-27139
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially …

Mar 1, 2024
CVE-2024-27138
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be …

Mar 1, 2024
CVE-2024-1624
9.4 CRITICAL

An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release …

Mar 1, 2024
CVE-2024-2067
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. …

Mar 1, 2024
CVE-2024-2066
2.4 LOW

A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-computer.php. …

Mar 1, 2024
CVE-2024-2065
3.5 LOW

A vulnerability was found in SourceCodester Barangay Population Monitoring System up to 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-27497
8.8 HIGH

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

Mar 1, 2024
CVE-2024-0967
4.3 MEDIUM

A potential vulnerability has been identified in OpenText / Micro Focus ArcSight Enterprise Security Manager (ESM). The vulnerability could be remotely exploited.

Mar 1, 2024
CVE-2023-50378
6.1 MEDIUM

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited …

Mar 1, 2024
CVE-2024-2064
4.3 MEDIUM

A vulnerability has been found in rahman SelectCours 1.0 and classified as problematic. Affected by this vulnerability is the function getCacheNames of the file CacheController.java …

Mar 1, 2024
CVE-2024-27572
7.5 HIGH

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27571
7.5 HIGH

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27570
7.5 HIGH

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27569
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27568
6.5 MEDIUM

LBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the apn_name_3g parameter in the setupEC20Apn function. This vulnerability allows attackers to cause a …

Mar 1, 2024
CVE-2024-27567
6.5 MEDIUM

LBT T300- T390 v2.2.1.8 were discovered to contain a stack overflow via the vpn_client_ip parameter in the config_vpn_pptp function. This vulnerability allows attackers to cause …

Mar 1, 2024
CVE-2024-24907
7.6 HIGH

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in the Filters page. An adjacent network high privileged attacker …

Mar 1, 2024
CVE-2024-24905
7.6 HIGH

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this …

Mar 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.