CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-39683
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher …

Feb 9, 2024
CVE-2023-31506
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover …

Feb 9, 2024
CVE-2024-1122
5.3 MEDIUM

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Feb 9, 2024
CVE-2024-0842
7.5 HIGH

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. …

Feb 9, 2024
CVE-2024-0657
4.4 MEDIUM

The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as 'ilj_settings_field_links_per_page' in …

Feb 9, 2024
CVE-2023-51761
8.3 HIGH

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

Feb 9, 2024
CVE-2023-49716
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

Feb 9, 2024
CVE-2023-46687
9.8 CRITICAL

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

Feb 9, 2024
CVE-2023-43609
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

Feb 9, 2024
CVE-2024-24819
5.3 MEDIUM

icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form …

Feb 9, 2024
CVE-2024-23639
5.1 MEDIUM

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the …

Feb 9, 2024
CVE-2024-22332
6.5 MEDIUM

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Feb 9, 2024
CVE-2024-22318
5.1 MEDIUM

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker …

Feb 9, 2024
CVE-2024-1353
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the …

Feb 9, 2024
CVE-2023-45191
7.5 HIGH

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM …

Feb 9, 2024
CVE-2023-45190
5.1 MEDIUM

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could …

Feb 9, 2024
CVE-2023-45187
6.3 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user …

Feb 9, 2024
CVE-2023-42016
4.3 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. …

Feb 9, 2024
CVE-2023-32341
6.5 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled …

Feb 9, 2024
CVE-2024-24829
4.3 MEDIUM

Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such …

Feb 9, 2024
CVE-2024-24825
9.1 CRITICAL

DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose …

Feb 9, 2024
CVE-2024-24821
8.8 HIGH

Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of …

Feb 9, 2024
CVE-2024-24820
8.3 HIGH

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring …

Feb 9, 2024
CVE-2024-25107
4.9 MEDIUM

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. On Special:WikiDiscover, the `Language::date` function is used when making the …

Feb 8, 2024
CVE-2024-25106
9.1 CRITICAL

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in …

Feb 8, 2024
CVE-2024-24830
9.9 CRITICAL

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the …

Feb 8, 2024
CVE-2023-51630
6.1 MEDIUM

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. …

Feb 8, 2024
CVE-2023-47132
9.8 CRITICAL

An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

Feb 8, 2024
CVE-2023-47131
7.5 HIGH

The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

Feb 8, 2024
CVE-2023-40264
4.3 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.

Feb 8, 2024
CVE-2023-40263
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

Feb 8, 2024
CVE-2023-40262
6.1 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration …

Feb 8, 2024
CVE-2022-0931

Rejected reason: Red Hat Product Security does not consider this to be a vulnerability. Upstream has not acknowledged this issue as a security flaw.

Feb 8, 2024
CVE-2024-24393
9.8 CRITICAL

File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

Feb 8, 2024
CVE-2023-49101
6.1 MEDIUM

WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage …

Feb 8, 2024
CVE-2023-40266
9.8 CRITICAL

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

Feb 8, 2024
CVE-2023-40265
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

Feb 8, 2024
CVE-2023-27001
8.8 HIGH

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting …

Feb 8, 2024
CVE-2023-25365
7.8 HIGH

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

Feb 8, 2024
CVE-2024-24499

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1007. Reason: This candidate is a duplicate of CVE-2024-1007. Notes: All CVE users should reference CVE-2024-1007 …

Feb 8, 2024
CVE-2024-24498

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1008. Reason: This candidate is a duplicate of CVE-2024-1008. Notes: All CVE users should reference CVE-2024-1008 …

Feb 8, 2024
CVE-2024-24497

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1009. Reason: This candidate is a duplicate of CVE-2024-1009. Notes: All CVE users should reference CVE-2024-1009 …

Feb 8, 2024
CVE-2024-24496
9.8 CRITICAL

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

Feb 8, 2024
CVE-2024-24495
9.8 CRITICAL

SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

Feb 8, 2024
CVE-2024-24494
6.1 MEDIUM

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, …

Feb 8, 2024
CVE-2024-23756
7.5 HIGH

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as …

Feb 8, 2024
CVE-2024-24115
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML …

Feb 8, 2024
CVE-2024-23660
7.5 HIGH

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the …

Feb 8, 2024
CVE-2024-22836
9.8 CRITICAL

An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system …

Feb 8, 2024
CVE-2024-1329
7.7 HIGH

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad …

Feb 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.