CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24133
9.8 CRITICAL

Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

Feb 7, 2024
CVE-2024-24131
6.1 MEDIUM

SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.

Feb 7, 2024
CVE-2024-24130
6.1 MEDIUM

Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.

Feb 7, 2024
CVE-2023-39196
5.3 MEDIUM

Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The …

Feb 7, 2024
CVE-2024-1118
8.8 HIGH

The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up …

Feb 7, 2024
CVE-2024-1110
5.3 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in …

Feb 7, 2024
CVE-2024-1109
5.3 MEDIUM

The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() …

Feb 7, 2024
CVE-2023-51437
7.4 HIGH

Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. …

Feb 7, 2024
CVE-2024-24311
7.5 HIGH

Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal …

Feb 7, 2024
CVE-2024-24304
7.5 HIGH

In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.

Feb 7, 2024
CVE-2024-24303
9.8 CRITICAL

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information …

Feb 7, 2024
CVE-2023-46914
9.8 CRITICAL

SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive …

Feb 7, 2024
CVE-2024-1079
5.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_show_results() function in all …

Feb 7, 2024
CVE-2024-1078
4.3 MEDIUM

The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ays_quick_start() and add_question_rows() functions …

Feb 7, 2024
CVE-2024-0977
4.4 MEDIUM

The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image URLs in the …

Feb 7, 2024
CVE-2023-40355
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code …

Feb 7, 2024
CVE-2024-1055
5.4 MEDIUM

The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's buttons in all …

Feb 7, 2024
CVE-2024-1037
6.1 MEDIUM

The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up …

Feb 7, 2024
CVE-2024-0628
3.8 LOW

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed …

Feb 7, 2024
CVE-2024-0256
6.4 MEDIUM

The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and …

Feb 7, 2024
CVE-2024-23447
5.3 MEDIUM

An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write …

Feb 7, 2024
CVE-2024-23446
6.5 MEDIUM

An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the …

Feb 7, 2024
CVE-2024-24810
8.2 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow …

Feb 7, 2024
CVE-2024-0849
5.0 MEDIUM

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

Feb 7, 2024
CVE-2023-6388
5.0 MEDIUM

Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF.

Feb 7, 2024
CVE-2024-1269
2.4 LOW

A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /supplier.php. The …

Feb 7, 2024
CVE-2024-1268
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The …

Feb 7, 2024
CVE-2024-24019
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 7, 2024
CVE-2024-22022
8.8 HIGH

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used …

Feb 7, 2024
CVE-2024-22021
4.3 MEDIUM

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one …

Feb 7, 2024
CVE-2024-1267
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of …

Feb 7, 2024
CVE-2024-1266
2.4 LOW

A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php …

Feb 7, 2024
CVE-2024-24004
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24002
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24001
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass …

Feb 7, 2024
CVE-2024-1284
9.8 CRITICAL

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-1283
9.8 CRITICAL

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-1265
2.4 LOW

A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the …

Feb 7, 2024
CVE-2024-1264
6.3 MEDIUM

A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the …

Feb 7, 2024
CVE-2024-0971
6.5 MEDIUM

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

Feb 7, 2024
CVE-2024-0955
4.8 MEDIUM

A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead …

Feb 7, 2024
CVE-2024-24255
4.2 MEDIUM

A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.

Feb 6, 2024
CVE-2024-22388
5.9 MEDIUM

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and …

Feb 6, 2024
CVE-2024-1263
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of …

Feb 6, 2024
CVE-2024-1262
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file …

Feb 6, 2024
CVE-2024-24680
7.5 HIGH

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a …

Feb 6, 2024
CVE-2024-24577
8.6 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-24575
7.5 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-24254
4.2 MEDIUM

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and …

Feb 6, 2024
CVE-2024-22520
8.2 HIGH

An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.