CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-4437
3.5 LOW

A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality …

Feb 12, 2024
CVE-2024-22230
6.4 MEDIUM

Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the …

Feb 12, 2024
CVE-2024-22228
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Feb 12, 2024
CVE-2024-22227
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-22226
3.3 LOW

Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain …

Feb 12, 2024
CVE-2024-22225
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-22224
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Feb 12, 2024
CVE-2024-22223
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially …

Feb 12, 2024
CVE-2024-22222
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially …

Feb 12, 2024
CVE-2024-22221
4.5 MEDIUM

Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.

Feb 12, 2024
CVE-2024-0170
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping …

Feb 12, 2024
CVE-2024-0169
5.7 MEDIUM

Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote …

Feb 12, 2024
CVE-2024-0168
7.8 HIGH

Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the …

Feb 12, 2024
CVE-2024-0167
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-0166
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-0165
7.8 HIGH

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2024-0164
7.8 HIGH

Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading …

Feb 12, 2024
CVE-2022-34311
4.3 MEDIUM

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session …

Feb 12, 2024
CVE-2022-34309
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2022-38714
4.9 MEDIUM

IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: …

Feb 12, 2024
CVE-2022-34310
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2024-25360
5.3 MEDIUM

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

Feb 12, 2024
CVE-2024-0566
7.2 HIGH

The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a …

Feb 12, 2024
CVE-2024-0421
5.3 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an …

Feb 12, 2024
CVE-2024-0420
5.4 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing …

Feb 12, 2024
CVE-2024-0250
6.1 MEDIUM

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php …

Feb 12, 2024
CVE-2024-0248
4.3 MEDIUM

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as …

Feb 12, 2024
CVE-2023-7233
4.8 MEDIUM

The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6591
4.8 MEDIUM

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 12, 2024
CVE-2023-6501
4.3 MEDIUM

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Feb 12, 2024
CVE-2023-6499
5.4 MEDIUM

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 12, 2024
CVE-2023-6294
7.2 HIGH

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator …

Feb 12, 2024
CVE-2023-6082
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6081
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6036
9.8 CRITICAL

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and …

Feb 12, 2024
CVE-2024-1420

Rejected reason: **REJECT** This is a duplicate of CVE-2024-1049. Please use CVE-2024-1049 instead.

Feb 12, 2024
CVE-2023-6681
5.3 MEDIUM

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary …

Feb 12, 2024
CVE-2024-1062
5.5 MEDIUM

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in …

Feb 12, 2024
CVE-2024-1439
6.5 MEDIUM

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with …

Feb 12, 2024
CVE-2024-24935
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WpSimpleTools Basic Log Viewer.This issue affects Basic Log Viewer: from n/a through 1.0.4.

Feb 12, 2024
CVE-2024-24929
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

Feb 12, 2024
CVE-2024-24887
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This …

Feb 12, 2024
CVE-2024-24884
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.

Feb 12, 2024
CVE-2024-24875
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

Feb 12, 2024
CVE-2024-23512
8.7 HIGH

Deserialization of Untrusted Data vulnerability in wpxpo ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks.This issue affects ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks: …

Feb 12, 2024
CVE-2023-46615
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

Feb 12, 2024
CVE-2023-41708
5.4 MEDIUM

References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script …

Feb 12, 2024
CVE-2023-41707
6.5 MEDIUM

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the …

Feb 12, 2024
CVE-2023-41706
6.5 MEDIUM

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App …

Feb 12, 2024
CVE-2023-41705
6.5 MEDIUM

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the …

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.