CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22241
4.3 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner …

Feb 6, 2024
CVE-2024-22240
4.9 MEDIUM

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to …

Feb 6, 2024
CVE-2024-22239
5.3 MEDIUM

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2024-22238
6.4 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user …

Feb 6, 2024
CVE-2024-22237
7.8 HIGH

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2024-1257
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads …

Feb 6, 2024
CVE-2024-1256
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to …

Feb 6, 2024
CVE-2024-1255
5.3 MEDIUM

A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The …

Feb 6, 2024
CVE-2024-1254
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the …

Feb 6, 2024
CVE-2024-1048
3.3 LOW

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv …

Feb 6, 2024
CVE-2023-40545
8.8 HIGH

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

Feb 6, 2024
CVE-2024-22331
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy …

Feb 6, 2024
CVE-2024-1253
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is some …

Feb 6, 2024
CVE-2024-1252
5.5 MEDIUM

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file …

Feb 6, 2024
CVE-2023-47618
7.2 HIGH

A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-47617
7.2 HIGH

A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A …

Feb 6, 2024
CVE-2023-47209
7.2 HIGH

A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-47167
7.2 HIGH

A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially …

Feb 6, 2024
CVE-2023-46683
7.2 HIGH

A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A …

Feb 6, 2024
CVE-2023-43482
7.2 HIGH

A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP …

Feb 6, 2024
CVE-2023-42664
7.2 HIGH

A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. …

Feb 6, 2024
CVE-2023-36498
7.2 HIGH

A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted …

Feb 6, 2024
CVE-2024-24291
6.1 MEDIUM

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

Feb 6, 2024
CVE-2024-24015
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 6, 2024
CVE-2024-24013
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection …

Feb 6, 2024
CVE-2024-24000
9.8 CRITICAL

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced …

Feb 6, 2024
CVE-2024-23344
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process …

Feb 6, 2024
CVE-2024-1251
5.5 MEDIUM

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The …

Feb 6, 2024
CVE-2023-50395
8.0 HIGH

SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

Feb 6, 2024
CVE-2023-46183
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force …

Feb 6, 2024
CVE-2023-35188
8.0 HIGH

SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

Feb 6, 2024
CVE-2024-24594
9.9 CRITICAL

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a …

Feb 6, 2024
CVE-2024-24593
9.6 CRITICAL

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote …

Feb 6, 2024
CVE-2024-24592
9.8 CRITICAL

Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and …

Feb 6, 2024
CVE-2024-24591
8.0 HIGH

A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write …

Feb 6, 2024
CVE-2024-24590
8.0 HIGH

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact …

Feb 6, 2024
CVE-2024-0911
5.5 MEDIUM

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a …

Feb 6, 2024
CVE-2023-5584

Rejected reason: We have rejected this CVE as it was determined a non-security issue by the vendor.

Feb 6, 2024
CVE-2024-0690
5.0 MEDIUM

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in …

Feb 6, 2024
CVE-2024-24943
5.3 MEDIUM

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Feb 6, 2024
CVE-2024-24942
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

Feb 6, 2024
CVE-2024-24941
6.1 MEDIUM

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

Feb 6, 2024
CVE-2024-24940
2.8 LOW

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

Feb 6, 2024
CVE-2024-24939
3.3 LOW

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Feb 6, 2024
CVE-2024-24938
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

Feb 6, 2024
CVE-2024-24937
4.6 MEDIUM

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

Feb 6, 2024
CVE-2024-24936
4.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

Feb 6, 2024
CVE-2024-23917
9.8 CRITICAL

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

Feb 6, 2024
CVE-2024-23673
8.5 HIGH

Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. …

Feb 6, 2024
CVE-2024-25140
9.8 CRITICAL

A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), …

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.