CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-29179
6.5 MEDIUM

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 …

Feb 22, 2024
CVE-2024-26491
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts …

Feb 22, 2024
CVE-2024-26490
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a …

Feb 22, 2024
CVE-2024-26489
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or …

Feb 22, 2024
CVE-2024-1053
4.3 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action …

Feb 22, 2024
CVE-2024-0903
5.4 MEDIUM

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 22, 2024
CVE-2024-27283
7.2 HIGH

A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to arbitrary locations on the server on …

Feb 22, 2024
CVE-2024-26484
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML …

Feb 22, 2024
CVE-2024-26483
8.8 HIGH

An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.

Feb 22, 2024
CVE-2024-26482
7.1 HIGH

An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because …

Feb 22, 2024
CVE-2024-26481
4.7 MEDIUM

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

Feb 22, 2024
CVE-2024-25801
6.1 MEDIUM

SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) …

Feb 22, 2024
CVE-2024-23137
7.8 HIGH

A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other …

Feb 22, 2024
CVE-2024-23136
7.8 HIGH

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other …

Feb 22, 2024
CVE-2024-23135
7.8 HIGH

A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk applications can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could …

Feb 22, 2024
CVE-2024-23134
7.8 HIGH

A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could …

Feb 22, 2024
CVE-2024-23133
7.8 HIGH

A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability …

Feb 22, 2024
CVE-2024-23132
7.8 HIGH

A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write access violation. This vulnerability …

Feb 22, 2024
CVE-2024-23131
7.8 HIGH

A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write …

Feb 22, 2024
CVE-2024-23130
7.8 HIGH

A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. …

Feb 22, 2024
CVE-2024-23129
7.8 HIGH

A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write …

Feb 22, 2024
CVE-2024-23128
7.8 HIGH

A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. …

Feb 22, 2024
CVE-2024-23127
7.8 HIGH

A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cause a Heap-based Overflow. …

Feb 22, 2024
CVE-2024-23126
7.8 HIGH

A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this …

Feb 22, 2024
CVE-2024-23125
7.8 HIGH

A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this …

Feb 22, 2024
CVE-2024-23124
7.8 HIGH

A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Feb 22, 2024
CVE-2024-23123
7.8 HIGH

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …

Feb 22, 2024
CVE-2024-23122
7.8 HIGH

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Feb 22, 2024
CVE-2024-23121
7.8 HIGH

A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Feb 22, 2024
CVE-2024-25423
7.0 HIGH

An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.

Feb 22, 2024
CVE-2024-25251
8.8 HIGH

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

Feb 22, 2024
CVE-2023-4895
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-23120
7.8 HIGH

A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor …

Feb 22, 2024
CVE-2024-1525
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-1451
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page …

Feb 22, 2024
CVE-2024-0861
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-0446
7.8 HIGH

A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious …

Feb 22, 2024
CVE-2024-0410
7.7 HIGH

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer …

Feb 22, 2024
CVE-2023-6477
6.7 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-26148
6.1 MEDIUM

Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users …

Feb 21, 2024
CVE-2024-26147
7.5 HIGH

Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml …

Feb 21, 2024
CVE-2023-3509
3.7 LOW

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before …

Feb 21, 2024
CVE-2023-52155
7.2 HIGH

A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through …

Feb 21, 2024
CVE-2023-52154
7.2 HIGH

File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.

Feb 21, 2024
CVE-2023-52153
9.8 CRITICAL

A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

Feb 21, 2024
CVE-2023-51828
9.8 CRITICAL

A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter …

Feb 21, 2024
CVE-2024-25124
9.4 CRITICAL

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application …

Feb 21, 2024
CVE-2024-23654
4.1 MEDIUM

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF …

Feb 21, 2024
CVE-2023-38844
7.5 HIGH

SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

Feb 21, 2024
CVE-2023-37177
9.8 CRITICAL

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the …

Feb 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.