CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-30970
6.5 MEDIUM

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …

Jan 29, 2024
CVE-2023-22836
3.5 LOW

In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed …

Jan 29, 2024
CVE-2024-1016
5.3 MEDIUM

A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command …

Jan 29, 2024
CVE-2024-23828
8.8 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value …

Jan 29, 2024
CVE-2024-1011
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component …

Jan 29, 2024
CVE-2024-1010
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file edit-profile.php. The manipulation …

Jan 29, 2024
CVE-2024-1009
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 29, 2024
CVE-2024-0788
6.6 MEDIUM

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys …

Jan 29, 2024
CVE-2023-40551
5.1 MEDIUM

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive …

Jan 29, 2024
CVE-2023-40550
5.5 MEDIUM

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's …

Jan 29, 2024
CVE-2023-40549
6.2 MEDIUM

An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw …

Jan 29, 2024
CVE-2023-40546
6.2 MEDIUM

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it …

Jan 29, 2024
CVE-2023-1705
8.4 HIGH

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

Jan 29, 2024
CVE-2024-23827
9.8 CRITICAL

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if …

Jan 29, 2024
CVE-2024-23826
6.8 MEDIUM

spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar image, an authenticated user …

Jan 29, 2024
CVE-2024-23822
5.4 MEDIUM

Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a …

Jan 29, 2024
CVE-2024-23441
5.5 MEDIUM

Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.

Jan 29, 2024
CVE-2024-1008
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 29, 2024
CVE-2024-1007
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. …

Jan 29, 2024
CVE-2024-1006
7.3 HIGH

A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file …

Jan 29, 2024
CVE-2024-1005
5.3 MEDIUM

A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file …

Jan 29, 2024
CVE-2024-1004
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 29, 2024
CVE-2024-1003
7.2 HIGH

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file …

Jan 29, 2024
CVE-2023-7204
7.5 HIGH

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

Jan 29, 2024
CVE-2023-7200
6.1 MEDIUM

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 29, 2024
CVE-2023-7199
5.3 MEDIUM

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted …

Jan 29, 2024
CVE-2023-7089
5.4 MEDIUM

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author …

Jan 29, 2024
CVE-2023-7074
8.8 HIGH

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 29, 2024
CVE-2023-6946
8.8 HIGH

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6633
4.3 MEDIUM

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in …

Jan 29, 2024
CVE-2023-6530
5.4 MEDIUM

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 29, 2024
CVE-2023-6503
5.4 MEDIUM

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Jan 29, 2024
CVE-2023-6391
8.8 HIGH

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 29, 2024
CVE-2023-6390
8.8 HIGH

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6389
6.1 MEDIUM

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users …

Jan 29, 2024
CVE-2023-6279
7.1 HIGH

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update …

Jan 29, 2024
CVE-2023-6278
6.1 MEDIUM

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting …

Jan 29, 2024
CVE-2023-6165
4.8 MEDIUM

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 29, 2024
CVE-2023-5956
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5943
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5124
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, …

Jan 29, 2024
CVE-2023-40548
7.4 HIGH

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from …

Jan 29, 2024
CVE-2024-23747
7.5 HIGH

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling …

Jan 29, 2024
CVE-2024-22559
5.4 MEDIUM

LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

Jan 29, 2024
CVE-2024-1015
9.8 CRITICAL

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the …

Jan 29, 2024
CVE-2024-1014
6.2 MEDIUM

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending …

Jan 29, 2024
CVE-2024-1002
7.2 HIGH

A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 29, 2024
CVE-2024-1001
7.2 HIGH

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to …

Jan 29, 2024
CVE-2024-1000
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2024-0999
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.