CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6557
5.3 MEDIUM

The The Events Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.2.8.2 via the route function …

Feb 5, 2024
CVE-2023-6526
6.4 MEDIUM

The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the …

Feb 5, 2024
CVE-2023-4637
4.3 MEDIUM

The WPvivid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the restore() and get_restore_progress() function in …

Feb 5, 2024
CVE-2023-34042
4.1 MEDIUM

The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access …

Feb 5, 2024
CVE-2023-22819
4.9 MEDIUM

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting …

Feb 5, 2024
CVE-2023-22817
5.5 MEDIUM

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point …

Feb 5, 2024
CVE-2024-24807
2.7 LOW

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag …

Feb 5, 2024
CVE-2024-24574
6.5 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to …

Feb 5, 2024
CVE-2024-24559
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `IR` for `sha3_64`. Concretely, …

Feb 5, 2024
CVE-2024-24543
9.8 CRITICAL

Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or …

Feb 5, 2024
CVE-2024-22208
6.5 MEDIUM

phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ' functionality allows any unauthenticated actor …

Feb 5, 2024
CVE-2024-1052
8.0 HIGH

Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain …

Feb 5, 2024
CVE-2024-0202
5.9 MEDIUM

A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS …

Feb 5, 2024
CVE-2023-51951
9.8 CRITICAL

SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

Feb 5, 2024
CVE-2023-50782
7.5 HIGH

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …

Feb 5, 2024
CVE-2023-50781
7.5 HIGH

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, …

Feb 5, 2024
CVE-2023-27318
6.5 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.13 are susceptible to a Denial of Service (DoS) vulnerability. A successful exploit could lead to a crash …

Feb 5, 2024
CVE-2024-22567
8.8 HIGH

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

Feb 5, 2024
CVE-2024-22202
5.7 MEDIUM

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to …

Feb 5, 2024
CVE-2024-24396
6.1 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2024-24267
7.5 HIGH

gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

Feb 5, 2024
CVE-2024-24266
7.5 HIGH

gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src/filters/dasher.c.

Feb 5, 2024
CVE-2024-24265
7.5 HIGH

gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

Feb 5, 2024
CVE-2024-24263
7.5 HIGH

Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.

Feb 5, 2024
CVE-2024-24262
7.5 HIGH

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c.

Feb 5, 2024
CVE-2024-24260
7.5 HIGH

media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c.

Feb 5, 2024
CVE-2024-24259
7.5 HIGH

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

Feb 5, 2024
CVE-2024-24258
7.5 HIGH

freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

Feb 5, 2024
CVE-2023-6874
7.5 HIGH

Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

Feb 5, 2024
CVE-2023-6028
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a …

Feb 5, 2024
CVE-2024-0953
6.1 MEDIUM

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified …

Feb 5, 2024
CVE-2024-24469
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

Feb 5, 2024
CVE-2024-24468
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.

Feb 5, 2024
CVE-2024-24397
5.4 MEDIUM

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 5, 2024
CVE-2024-23054
9.8 CRITICAL

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components …

Feb 5, 2024
CVE-2024-0323
9.8 CRITICAL

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the …

Feb 5, 2024
CVE-2023-47355
7.5 HIGH

The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that …

Feb 5, 2024
CVE-2024-24768
6.5 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure …

Feb 5, 2024
CVE-2024-24762
7.5 HIGH

`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. …

Feb 5, 2024
CVE-2023-7216
5.3 MEDIUM

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a …

Feb 5, 2024
CVE-2023-52138
8.2 HIGH

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to …

Feb 5, 2024
CVE-2024-23109
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2024-23108
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2024-1225
7.3 HIGH

A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file …

Feb 5, 2024
CVE-2023-5643
7.8 HIGH

Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Feb 5, 2024
CVE-2023-5249
7.0 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Feb 5, 2024
CVE-2021-4436
9.8 CRITICAL

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , …

Feb 5, 2024
CVE-2024-24864
5.3 MEDIUM

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to …

Feb 5, 2024
CVE-2024-24861
3.3 LOW

A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly …

Feb 5, 2024
CVE-2024-24860
4.6 MEDIUM

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.