CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45190
5.1 MEDIUM

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could …

Feb 9, 2024
CVE-2023-45187
6.3 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user …

Feb 9, 2024
CVE-2023-42016
4.3 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. …

Feb 9, 2024
CVE-2023-32341
6.5 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled …

Feb 9, 2024
CVE-2024-24829
4.3 MEDIUM

Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such …

Feb 9, 2024
CVE-2024-24825
9.1 CRITICAL

DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose …

Feb 9, 2024
CVE-2024-24821
8.8 HIGH

Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of …

Feb 9, 2024
CVE-2024-24820
8.3 HIGH

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring …

Feb 9, 2024
CVE-2024-25107
4.9 MEDIUM

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. On Special:WikiDiscover, the `Language::date` function is used when making the …

Feb 8, 2024
CVE-2024-25106
9.1 CRITICAL

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in …

Feb 8, 2024
CVE-2024-24830
9.9 CRITICAL

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the …

Feb 8, 2024
CVE-2023-51630
6.1 MEDIUM

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. …

Feb 8, 2024
CVE-2023-47132
9.8 CRITICAL

An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

Feb 8, 2024
CVE-2023-47131
7.5 HIGH

The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

Feb 8, 2024
CVE-2023-40264
4.3 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.

Feb 8, 2024
CVE-2023-40263
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

Feb 8, 2024
CVE-2023-40262
6.1 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration …

Feb 8, 2024
CVE-2022-0931

Rejected reason: Red Hat Product Security does not consider this to be a vulnerability. Upstream has not acknowledged this issue as a security flaw.

Feb 8, 2024
CVE-2024-24393
9.8 CRITICAL

File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

Feb 8, 2024
CVE-2023-49101
6.1 MEDIUM

WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage …

Feb 8, 2024
CVE-2023-40266
9.8 CRITICAL

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

Feb 8, 2024
CVE-2023-40265
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

Feb 8, 2024
CVE-2023-27001
8.8 HIGH

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting …

Feb 8, 2024
CVE-2023-25365
7.8 HIGH

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

Feb 8, 2024
CVE-2024-24499

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1007. Reason: This candidate is a duplicate of CVE-2024-1007. Notes: All CVE users should reference CVE-2024-1007 …

Feb 8, 2024
CVE-2024-24498

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1008. Reason: This candidate is a duplicate of CVE-2024-1008. Notes: All CVE users should reference CVE-2024-1008 …

Feb 8, 2024
CVE-2024-24497

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1009. Reason: This candidate is a duplicate of CVE-2024-1009. Notes: All CVE users should reference CVE-2024-1009 …

Feb 8, 2024
CVE-2024-24496
9.8 CRITICAL

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

Feb 8, 2024
CVE-2024-24495
9.8 CRITICAL

SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

Feb 8, 2024
CVE-2024-24494
6.1 MEDIUM

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, …

Feb 8, 2024
CVE-2024-23756
7.5 HIGH

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as …

Feb 8, 2024
CVE-2024-24115
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML …

Feb 8, 2024
CVE-2024-23660
7.5 HIGH

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the …

Feb 8, 2024
CVE-2024-22836
9.8 CRITICAL

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system …

Feb 8, 2024
CVE-2024-1329
7.7 HIGH

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad …

Feb 8, 2024
CVE-2024-0242
7.3 HIGH

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

Feb 8, 2024
CVE-2024-24215
5.3 MEDIUM

An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.

Feb 8, 2024
CVE-2024-23764
6.7 MEDIUM

Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server …

Feb 8, 2024
CVE-2024-22795
7.0 HIGH

Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

Feb 8, 2024
CVE-2024-24321
9.8 CRITICAL

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

Feb 8, 2024
CVE-2024-24213
9.8 CRITICAL

Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended …

Feb 8, 2024
CVE-2023-50061
9.8 CRITICAL

PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

Feb 8, 2024
CVE-2024-25191
9.8 CRITICAL

php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

Feb 8, 2024
CVE-2024-25190
9.8 CRITICAL

l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

Feb 8, 2024
CVE-2024-25189
9.8 CRITICAL

libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

Feb 8, 2024
CVE-2023-42282
9.8 CRITICAL

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Feb 8, 2024
CVE-2023-47020
8.8 HIGH

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user …

Feb 8, 2024
CVE-2024-24834
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net …

Feb 8, 2024
CVE-2024-24878
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | Webdados Portugal CTT Tracking for WooCommerce portugal-ctt-tracking-woocommerce.This issue affects Portugal …

Feb 8, 2024
CVE-2024-24877
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder …

Feb 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.