CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1064
7.5 HIGH

A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) …

Feb 3, 2024
CVE-2023-49950
5.4 MEDIUM

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template …

Feb 3, 2024
CVE-2023-44031
7.5 HIGH

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted …

Feb 3, 2024
CVE-2023-43183
8.8 HIGH

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack …

Feb 3, 2024
CVE-2024-23550
6.2 MEDIUM

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

Feb 3, 2024
CVE-2024-0909
5.3 MEDIUM

The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient …

Feb 3, 2024
CVE-2024-0895
5.4 MEDIUM

The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and …

Feb 3, 2024
CVE-2023-37528
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during …

Feb 3, 2024
CVE-2024-1200
5.3 MEDIUM

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation …

Feb 3, 2024
CVE-2023-43016
7.3 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-32329
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-32327
7.1 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to …

Feb 3, 2024
CVE-2023-31006
6.5 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to …

Feb 3, 2024
CVE-2023-31005
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-31004
8.3 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-30999
7.5 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an …

Feb 3, 2024
CVE-2024-1199
5.4 MEDIUM

A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 3, 2024
CVE-2024-1198
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the …

Feb 3, 2024
CVE-2024-1197
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file …

Feb 2, 2024
CVE-2024-1196
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component …

Feb 2, 2024
CVE-2024-1195
5.5 MEDIUM

A vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library ITopVpnCallbackProcess.sys …

Feb 2, 2024
CVE-2024-23553
3.0 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

Feb 2, 2024
CVE-2024-1194
3.3 LOW

A vulnerability classified as problematic has been found in Armcode AlienIP 2.41. Affected is an unknown function of the component Locate Host Handler. The manipulation …

Feb 2, 2024
CVE-2024-1193
3.3 LOW

A vulnerability was found in Navicat 12.0.29. It has been rated as problematic. This issue affects some unknown processing of the component MySQL Conecction Handler. …

Feb 2, 2024
CVE-2024-1190
3.3 LOW

A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the …

Feb 2, 2024
CVE-2024-1189
5.3 MEDIUM

A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Encryption Passphrase …

Feb 2, 2024
CVE-2023-37527
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code …

Feb 2, 2024
CVE-2024-1188
3.3 LOW

A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. …

Feb 2, 2024
CVE-2024-1187
3.3 LOW

A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the …

Feb 2, 2024
CVE-2024-24560
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls to external contracts are made, we write the input buffer starting …

Feb 2, 2024
CVE-2024-23635
6.1 MEDIUM

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation …

Feb 2, 2024
CVE-2024-1186
3.3 LOW

A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The …

Feb 2, 2024
CVE-2024-24760
8.8 HIGH

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < …

Feb 2, 2024
CVE-2024-24757
7.6 HIGH

open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. …

Feb 2, 2024
CVE-2024-24470
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

Feb 2, 2024
CVE-2024-24161
7.5 HIGH

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

Feb 2, 2024
CVE-2024-24160
5.4 MEDIUM

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

Feb 2, 2024
CVE-2024-24029
9.8 CRITICAL

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

Feb 2, 2024
CVE-2024-23831
7.5 HIGH

LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin …

Feb 2, 2024
CVE-2024-23824
4.7 MEDIUM

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload …

Feb 2, 2024
CVE-2024-22108
9.8 CRITICAL

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an …

Feb 2, 2024
CVE-2024-22107
7.2 HIGH

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated …

Feb 2, 2024
CVE-2024-1185
3.3 LOW

A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. …

Feb 2, 2024
CVE-2023-6387
7.5 HIGH

A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service …

Feb 2, 2024
CVE-2023-51838
7.5 HIGH

Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

Feb 2, 2024
CVE-2023-50359
3.4 LOW

An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated administrators to …

Feb 2, 2024
CVE-2023-47568
8.8 HIGH

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious …

Feb 2, 2024
CVE-2023-47567
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47566
6.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47564
8.0 HIGH

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.