CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21399
8.3 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 2, 2024
CVE-2023-50940
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information …

Feb 2, 2024
CVE-2023-50937
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50936
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. …

Feb 2, 2024
CVE-2023-50933
6.1 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

Feb 2, 2024
CVE-2023-50327
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50326
7.5 HIGH

IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force …

Feb 2, 2024
CVE-2024-22096
6.5 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific …

Feb 2, 2024
CVE-2024-22016
7.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege …

Feb 2, 2024
CVE-2024-21869
6.2 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker …

Feb 2, 2024
CVE-2024-21866
5.3 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it …

Feb 2, 2024
CVE-2024-21794
5.4 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

Feb 2, 2024
CVE-2024-21764
9.8 CRITICAL

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a …

Feb 2, 2024
CVE-2023-50939
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2024-24756
7.5 HIGH

Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. …

Feb 1, 2024
CVE-2024-23034
6.1 MEDIUM

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23033
6.1 MEDIUM

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23032
6.1 MEDIUM

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23031
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-22927
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-21852
8.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability …

Feb 1, 2024
CVE-2023-6221
7.7 HIGH

The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others …

Feb 1, 2024
CVE-2023-49617
10.0 CRITICAL

The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without …

Feb 1, 2024
CVE-2023-49610
8.1 HIGH

MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could …

Feb 1, 2024
CVE-2023-49115
7.5 HIGH

MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

Feb 1, 2024
CVE-2023-47867
8.8 HIGH

MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the …

Feb 1, 2024
CVE-2023-46706
9.1 CRITICAL

Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

Feb 1, 2024
CVE-2023-36496
7.7 HIGH

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

Feb 1, 2024
CVE-2024-24755
4.3 MEDIUM

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields …

Feb 1, 2024
CVE-2024-1040
4.4 MEDIUM

Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the …

Feb 1, 2024
CVE-2024-1039
9.8 CRITICAL

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management …

Feb 1, 2024
CVE-2024-0325
3.6 LOW

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.

Feb 1, 2024
CVE-2023-4472
9.8 CRITICAL

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated …

Feb 1, 2024
CVE-2023-47257
8.1 HIGH

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

Feb 1, 2024
CVE-2023-47256
5.5 MEDIUM

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

Feb 1, 2024
CVE-2024-24945
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or …

Feb 1, 2024
CVE-2024-24041
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or …

Feb 1, 2024
CVE-2024-24569
5.4 MEDIUM

The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal …

Feb 1, 2024
CVE-2023-5841
9.1 CRITICAL

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing …

Feb 1, 2024
CVE-2024-23645
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. Upgrade to 10.0.12.

Feb 1, 2024
CVE-2024-1167
5.5 MEDIUM

When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

Feb 1, 2024
CVE-2023-51446
5.9 MEDIUM

GLPI is a Free Asset and IT Management Software package. When authentication is made against a LDAP, the authentication form can be used to perform …

Feb 1, 2024
CVE-2024-24570
8.2 HIGH

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This …

Feb 1, 2024
CVE-2024-24561
9.8 CRITICAL

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account …

Feb 1, 2024
CVE-2024-24557
6.9 MEDIUM

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image …

Feb 1, 2024
CVE-2024-23832
9.4 CRITICAL

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all …

Feb 1, 2024
CVE-2024-24754
3.7 LOW

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda …

Feb 1, 2024
CVE-2024-24753
4.8 MEDIUM

Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it does not handle …

Feb 1, 2024
CVE-2024-24752
6.5 MEDIUM

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda …

Feb 1, 2024
CVE-2024-1141
5.5 MEDIUM

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

Feb 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.