CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24904
7.6 HIGH

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability. An adjacent network high privileged attacker could potentially exploit this …

Mar 1, 2024
CVE-2024-24903
8.0 HIGH

Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could …

Mar 1, 2024
CVE-2023-52497
6.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, …

Mar 1, 2024
CVE-2023-46951
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.

Mar 1, 2024
CVE-2023-46950
6.1 MEDIUM

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.

Mar 1, 2024
CVE-2024-2063
2.4 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Petrol Pump Management Software 1.0. Affected is an unknown function of the file /admin/app/profile_crud.php. …

Mar 1, 2024
CVE-2024-2062
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. This issue affects some unknown processing of the …

Mar 1, 2024
CVE-2024-2061
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. This vulnerability affects unknown code of the file /admin/edit_supplier.php. The manipulation …

Mar 1, 2024
CVE-2024-2060
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Petrol Pump Management Software 1.0. This affects an unknown part of the file /admin/app/login_crud.php. The …

Mar 1, 2024
CVE-2024-24906
7.6 HIGH

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain(s) a Stored Cross-Site Scripting Vulnerability in Policy page. An adjacent network high privileged attacker could …

Mar 1, 2024
CVE-2024-24900
5.8 MEDIUM

Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, …

Mar 1, 2024
CVE-2023-48674
6.8 MEDIUM

Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to …

Mar 1, 2024
CVE-2023-39254
6.7 MEDIUM

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially …

Mar 1, 2024
CVE-2024-2078
4.6 MEDIUM

A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially …

Mar 1, 2024
CVE-2024-2059
4.7 MEDIUM

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 1, 2024
CVE-2024-2057
6.3 MEDIUM

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the …

Mar 1, 2024
CVE-2024-2058
4.7 MEDIUM

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 1, 2024
CVE-2024-26280
4.7 MEDIUM

Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated Ops and Viewers users to view all information on audit logs, including dag names …

Mar 1, 2024
CVE-2024-22458
3.7 LOW

Dell Secure Connect Gateway, 5.18, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover …

Mar 1, 2024
CVE-2024-22457
7.1 HIGH

Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A remote low privileged attacker could potentially exploit …

Mar 1, 2024
CVE-2024-25972
8.3 HIGH

Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a network-adjacent unauthenticated attacker to …

Mar 1, 2024
CVE-2024-1120
5.3 MEDIUM

The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable …

Mar 1, 2024
CVE-2024-25091
9.1 CRITICAL

Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using …

Mar 1, 2024
CVE-2024-0692
8.8 HIGH

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote …

Mar 1, 2024
CVE-2024-27950
5.4 MEDIUM

Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Mar 1, 2024
CVE-2024-27949
5.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

Mar 1, 2024
CVE-2024-25554

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 1, 2024
CVE-2024-25553

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 1, 2024
CVE-2024-25552
7.8 HIGH

A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.

Mar 1, 2024
CVE-2023-52555
6.1 MEDIUM

In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.

Mar 1, 2024
CVE-2024-1859
8.8 HIGH

The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Mar 1, 2024
CVE-2024-25386
8.8 HIGH

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

Mar 1, 2024
CVE-2024-25293
9.3 CRITICAL

mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

Mar 1, 2024
CVE-2024-22891
9.8 CRITICAL

Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

Mar 1, 2024
CVE-2023-50312
5.3 MEDIUM

IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.2 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user …

Mar 1, 2024
CVE-2023-47716
6.3 MEDIUM

IBM CP4BA - Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a user to gain the privileges of another user under unusual circumstances. …

Mar 1, 2024
CVE-2023-38366
5.3 MEDIUM

IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a …

Mar 1, 2024
CVE-2023-50324
5.3 MEDIUM

IBM Cognos Command Center 10.2.4.1 and 10.2.5 exposes details the X-AspNet-Version Response Header that could allow an attacker to obtain information of the application environment …

Mar 1, 2024
CVE-2023-50305
5.1 MEDIUM

IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise …

Mar 1, 2024
CVE-2023-28949
6.5 MEDIUM

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

Mar 1, 2024
CVE-2023-28525
4.8 MEDIUM

IBM Engineering Requirements Management 9.7.2.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Mar 1, 2024
CVE-2024-25578
7.8 HIGH

MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within …

Mar 1, 2024
CVE-2024-22100
7.8 HIGH

MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary …

Mar 1, 2024
CVE-2024-1941
7.8 HIGH

Delta Electronics CNCSoft-B versions 1.0.0.4 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Mar 1, 2024
CVE-2024-2045
5.5 MEDIUM

Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application …

Mar 1, 2024
CVE-2024-2022
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 1, 2024
CVE-2024-2021
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. Affected is an unknown function of the file …

Mar 1, 2024
CVE-2024-0403
6.5 MEDIUM

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

Mar 1, 2024
CVE-2024-27294
7.3 HIGH

dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership …

Feb 29, 2024
CVE-2021-47068
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/nfc: fix use-after-free llcp_sock_bind/connect Commits 8a4cd82d ("nfc: fix refcount leak in llcp_sock_connect()") and c33b1cc62 ("nfc: …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.