CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25350
9.8 CRITICAL

SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.

Feb 28, 2024
CVE-2024-22983
8.1 HIGH

SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php …

Feb 28, 2024
CVE-2024-1972
3.5 LOW

A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Feb 28, 2024
CVE-2023-49338
7.5 HIGH

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

Feb 28, 2024
CVE-2023-45873
6.5 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Feb 28, 2024
CVE-2023-45859
7.6 HIGH

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check …

Feb 28, 2024
CVE-2023-25925
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system …

Feb 28, 2024
CVE-2023-25922
4.3 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 28, 2024
CVE-2024-27285
5.4 MEDIUM

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate …

Feb 28, 2024
CVE-2024-25859
7.1 HIGH

A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

Feb 28, 2024
CVE-2024-25435
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Feb 28, 2024
CVE-2024-25202
6.1 MEDIUM

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

Feb 28, 2024
CVE-2024-25170
9.1 CRITICAL

An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.

Feb 28, 2024
CVE-2024-25169
9.8 CRITICAL

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

Feb 28, 2024
CVE-2024-24148
7.5 HIGH

A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 28, 2024
CVE-2023-52048
4.7 MEDIUM

RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

Feb 28, 2024
CVE-2023-52047
8.8 HIGH

Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

Feb 28, 2024
CVE-2024-27948
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24.

Feb 28, 2024
CVE-2023-51692
4.3 MEDIUM

Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

Feb 28, 2024
CVE-2023-51533
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.

Feb 28, 2024
CVE-2024-27103
6.1 MEDIUM

Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, …

Feb 28, 2024
CVE-2024-26342
7.5 HIGH

A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

Feb 28, 2024
CVE-2024-1847
7.8 HIGH

Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in …

Feb 28, 2024
CVE-2024-21749
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.

Feb 28, 2024
CVE-2024-0560
6.3 MEDIUM

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy …

Feb 28, 2024
CVE-2023-52226
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

Feb 28, 2024
CVE-2023-52223
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.

Feb 28, 2024
CVE-2023-51683
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from …

Feb 28, 2024
CVE-2023-51681
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a …

Feb 28, 2024
CVE-2024-24705
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

Feb 28, 2024
CVE-2024-24702
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Feb 28, 2024
CVE-2023-6917
6.0 MEDIUM

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While …

Feb 28, 2024
CVE-2024-27515
7.2 HIGH

Osclass 5.1.2 is vulnerable to SQL Injection.

Feb 28, 2024
CVE-2024-25927
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postMash – custom post order.This issue affects postMash – …

Feb 28, 2024
CVE-2024-25910
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

Feb 28, 2024
CVE-2024-25902
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.

Feb 28, 2024
CVE-2024-24868
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & …

Feb 28, 2024
CVE-2024-21886
7.8 HIGH

A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in …

Feb 28, 2024
CVE-2024-21885
7.8 HIGH

A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs …

Feb 28, 2024
CVE-2024-1965
6.5 MEDIUM

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need …

Feb 28, 2024
CVE-2024-1808
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up …

Feb 28, 2024
CVE-2024-26016
4.3 MEDIUM

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Feb 28, 2024
CVE-2024-24779
5.0 MEDIUM

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to …

Feb 28, 2024
CVE-2024-24773
4.9 MEDIUM

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, …

Feb 28, 2024
CVE-2024-24772
4.3 MEDIUM

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics …

Feb 28, 2024
CVE-2024-1636
8.0 HIGH

Potential Cross-Site Scripting (XSS) in the page editing area.

Feb 28, 2024
CVE-2024-1632
8.8 HIGH

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

Feb 28, 2024
CVE-2024-27315
4.3 MEDIUM

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an …

Feb 28, 2024
CVE-2024-1861
4.3 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1860
6.5 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.