CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50658
7.5 HIGH

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50437
8.6 HIGH

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

Feb 29, 2024
CVE-2023-50436
5.3 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version …

Feb 29, 2024
CVE-2023-49932
5.4 MEDIUM

An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.

Feb 29, 2024
CVE-2023-49931
9.8 CRITICAL

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

Feb 29, 2024
CVE-2023-49930
9.8 CRITICAL

An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.

Feb 29, 2024
CVE-2023-49337
2.4 LOW

Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)

Feb 29, 2024
CVE-2023-48653
4.3 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events …

Feb 29, 2024
CVE-2023-48651
4.3 MEDIUM

Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.

Feb 29, 2024
CVE-2023-48650
4.8 MEDIUM

Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.

Feb 29, 2024
CVE-2023-47634
3.1 LOW

Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of …

Feb 29, 2024
CVE-2023-45874
4.3 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

Feb 29, 2024
CVE-2023-44347
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44346
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44345
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-44344
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44343
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44342
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Feb 29, 2024
CVE-2023-44341
5.5 MEDIUM

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …

Feb 29, 2024
CVE-2023-43769
6.3 MEDIUM

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

Feb 29, 2024
CVE-2023-41165
4.8 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and …

Feb 29, 2024
CVE-2023-38372
5.9 MEDIUM

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM …

Feb 29, 2024
CVE-2023-37531
3.3 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into …

Feb 29, 2024
CVE-2023-37530
3.0 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into …

Feb 29, 2024
CVE-2023-37529
3.0 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into …

Feb 29, 2024
CVE-2023-37495
5.9 MEDIUM

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® …

Feb 29, 2024
CVE-2023-34198
7.3 HIGH

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, …

Feb 29, 2024
CVE-2023-27151
6.1 MEDIUM

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity …

Feb 29, 2024
CVE-2023-25926
5.5 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Feb 29, 2024
CVE-2023-25921
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 29, 2024
CVE-2022-36677
6.1 MEDIUM

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

Feb 29, 2024
CVE-2022-34270
9.8 CRITICAL

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

Feb 29, 2024
CVE-2022-34269
8.8 HIGH

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to …

Feb 29, 2024
CVE-2024-26146
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a …

Feb 29, 2024
CVE-2024-26141
5.8 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with …

Feb 29, 2024
CVE-2024-25126
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, …

Feb 29, 2024
CVE-2024-26559
5.3 MEDIUM

An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.

Feb 28, 2024
CVE-2024-25579
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Feb 28, 2024
CVE-2024-25422
9.8 CRITICAL

SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.

Feb 28, 2024
CVE-2024-23910
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators …

Feb 28, 2024
CVE-2024-22532
6.5 MEDIUM

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

Feb 28, 2024
CVE-2024-21798
4.8 MEDIUM

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another …

Feb 28, 2024
CVE-2023-5617
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error …

Feb 28, 2024
CVE-2024-26476
3.5 LOW

An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.

Feb 28, 2024
CVE-2024-26450
5.4 MEDIUM

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery …

Feb 28, 2024
CVE-2024-25869
8.8 HIGH

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a …

Feb 28, 2024
CVE-2024-25868
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType …

Feb 28, 2024
CVE-2024-25867
9.1 CRITICAL

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and …

Feb 28, 2024
CVE-2024-25866
8.8 HIGH

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter …

Feb 28, 2024
CVE-2024-25351
3.8 LOW

SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.