CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40355
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code …

Feb 7, 2024
CVE-2024-1055
5.4 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all …

Feb 7, 2024
CVE-2024-1037
6.1 MEDIUM

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up …

Feb 7, 2024
CVE-2024-0628
3.8 LOW

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed …

Feb 7, 2024
CVE-2024-0256
6.4 MEDIUM

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and …

Feb 7, 2024
CVE-2024-23447
5.3 MEDIUM

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write …

Feb 7, 2024
CVE-2024-23446
6.5 MEDIUM

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the …

Feb 7, 2024
CVE-2024-24810
8.2 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow …

Feb 7, 2024
CVE-2024-0849
5.0 MEDIUM

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

Feb 7, 2024
CVE-2023-6388
5.0 MEDIUM

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

Feb 7, 2024
CVE-2024-1269
2.4 LOW

A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /supplier.php. The …

Feb 7, 2024
CVE-2024-1268
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The …

Feb 7, 2024
CVE-2024-24019
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 7, 2024
CVE-2024-22022
8.8 HIGH

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used …

Feb 7, 2024
CVE-2024-22021
4.3 MEDIUM

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one …

Feb 7, 2024
CVE-2024-1267
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of …

Feb 7, 2024
CVE-2024-1266
2.4 LOW

A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php …

Feb 7, 2024
CVE-2024-24004
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24002
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24001
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass …

Feb 7, 2024
CVE-2024-1284
9.8 CRITICAL

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-1283
9.8 CRITICAL

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-1265
2.4 LOW

A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the …

Feb 7, 2024
CVE-2024-1264
6.3 MEDIUM

A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the …

Feb 7, 2024
CVE-2024-0971
6.5 MEDIUM

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

Feb 7, 2024
CVE-2024-0955
4.8 MEDIUM

A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead …

Feb 7, 2024
CVE-2024-24255
4.2 MEDIUM

A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.

Feb 6, 2024
CVE-2024-22388
5.9 MEDIUM

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and …

Feb 6, 2024
CVE-2024-1263
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of …

Feb 6, 2024
CVE-2024-1262
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file …

Feb 6, 2024
CVE-2024-24680
7.5 HIGH

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a …

Feb 6, 2024
CVE-2024-24577
8.6 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-24575
7.5 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-24254
4.2 MEDIUM

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and …

Feb 6, 2024
CVE-2024-22520
8.2 HIGH

An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.

Feb 6, 2024
CVE-2024-22519
8.2 HIGH

An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.

Feb 6, 2024
CVE-2024-1261
6.3 MEDIUM

A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api/controllers/merchant/app/ComboController.php of the …

Feb 6, 2024
CVE-2024-1260
6.3 MEDIUM

A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the …

Feb 6, 2024
CVE-2023-45735
8.0 HIGH

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-45227
5.4 MEDIUM

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

Feb 6, 2024
CVE-2023-45222
5.4 MEDIUM

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the …

Feb 6, 2024
CVE-2023-45213
6.6 MEDIUM

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-42765
5.4 MEDIUM

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP …

Feb 6, 2024
CVE-2023-40544
5.7 MEDIUM

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via …

Feb 6, 2024
CVE-2023-40143
5.4 MEDIUM

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload …

Feb 6, 2024
CVE-2023-38579
8.0 HIGH

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered …

Feb 6, 2024
CVE-2024-22515
8.8 HIGH

Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

Feb 6, 2024
CVE-2024-22514
8.8 HIGH

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

Feb 6, 2024
CVE-2024-1259
6.3 MEDIUM

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 6, 2024
CVE-2024-1258
3.1 LOW

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.