CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22851
7.5 HIGH

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

Feb 2, 2024
CVE-2023-48645
7.8 HIGH

An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance …

Feb 2, 2024
CVE-2024-24524
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

Feb 2, 2024
CVE-2021-22281
6.3 MEDIUM

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Feb 2, 2024
CVE-2020-24682
7.2 HIGH

Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation …

Feb 2, 2024
CVE-2024-23978
9.8 CRITICAL

Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected …

Feb 2, 2024
CVE-2024-21863
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2024-21860
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Feb 2, 2024
CVE-2024-21851
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2024-21845
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2024-21780
7.5 HIGH

Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) …

Feb 2, 2024
CVE-2024-0285
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2023-49118
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2023-45734
4.2 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

Feb 2, 2024
CVE-2023-43756
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2021-22282
8.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from …

Feb 2, 2024
CVE-2020-24681
8.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from …

Feb 2, 2024
CVE-2024-1162
4.3 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due …

Feb 2, 2024
CVE-2024-1143
9.3 CRITICAL

Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

Feb 2, 2024
CVE-2024-1047
5.3 MEDIUM

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 2, 2024
CVE-2023-46045
7.8 HIGH

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically …

Feb 2, 2024
CVE-2024-24482
9.8 CRITICAL

Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

Feb 2, 2024
CVE-2024-21485
6.5 MEDIUM

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package …

Feb 2, 2024
CVE-2024-1073
6.4 MEDIUM

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due …

Feb 2, 2024
CVE-2024-0685
5.9 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via …

Feb 2, 2024
CVE-2023-38263
6.5 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-38020
4.3 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

Feb 2, 2024
CVE-2023-38019
8.1 HIGH

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Feb 2, 2024
CVE-2022-40744
4.8 MEDIUM

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 2, 2024
CVE-2024-22533
9.8 CRITICAL

Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the …

Feb 2, 2024
CVE-2024-22320
9.8 CRITICAL

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending …

Feb 2, 2024
CVE-2024-22319
8.1 HIGH

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an …

Feb 2, 2024
CVE-2023-46159
2.6 LOW

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force …

Feb 2, 2024
CVE-2024-23746
9.8 CRITICAL

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a …

Feb 2, 2024
CVE-2024-22903
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

Feb 2, 2024
CVE-2024-22902
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

Feb 2, 2024
CVE-2024-22901
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

Feb 2, 2024
CVE-2024-22900
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Feb 2, 2024
CVE-2024-22899
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Feb 2, 2024
CVE-2024-22779
8.8 HIGH

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

Feb 2, 2024
CVE-2023-50962
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

Feb 2, 2024
CVE-2023-50941
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using …

Feb 2, 2024
CVE-2023-50938
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Feb 2, 2024
CVE-2023-50935
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized …

Feb 2, 2024
CVE-2023-50934
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor …

Feb 2, 2024
CVE-2023-50328
3.7 LOW

IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

Feb 2, 2024
CVE-2023-48793
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

Feb 2, 2024
CVE-2023-48792
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

Feb 2, 2024
CVE-2023-46344
5.4 MEDIUM

A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting …

Feb 2, 2024
CVE-2023-32333
6.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.