CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6673
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-6672
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-47148
5.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured …

Feb 2, 2024
CVE-2023-47144
6.1 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Feb 2, 2024
CVE-2023-47143
10.0 CRITICAL

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. …

Feb 2, 2024
CVE-2024-1201
7.8 HIGH

Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious …

Feb 2, 2024
CVE-2024-0963
6.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, …

Feb 2, 2024
CVE-2024-0844
4.7 MEDIUM

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. …

Feb 2, 2024
CVE-2024-24388
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

Feb 2, 2024
CVE-2024-23895
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Feb 2, 2024
CVE-2024-0338
7.3 HIGH

A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug …

Feb 2, 2024
CVE-2023-51820
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

Feb 2, 2024
CVE-2023-51072
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious …

Feb 2, 2024
CVE-2023-50488
9.8 CRITICAL

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

Feb 2, 2024
CVE-2023-39611
7.5 HIGH

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web …

Feb 2, 2024
CVE-2024-22851
7.5 HIGH

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

Feb 2, 2024
CVE-2023-48645
7.8 HIGH

An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance …

Feb 2, 2024
CVE-2024-24524
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

Feb 2, 2024
CVE-2021-22281
6.3 MEDIUM

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Feb 2, 2024
CVE-2020-24682
7.2 HIGH

Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation …

Feb 2, 2024
CVE-2024-23978
9.8 CRITICAL

Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected …

Feb 2, 2024
CVE-2024-21863
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2024-21860
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Feb 2, 2024
CVE-2024-21851
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2024-21845
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2024-21780
7.5 HIGH

Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) …

Feb 2, 2024
CVE-2024-0285
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2023-49118
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2023-45734
4.2 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

Feb 2, 2024
CVE-2023-43756
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2021-22282
8.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from …

Feb 2, 2024
CVE-2020-24681
8.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from …

Feb 2, 2024
CVE-2024-1162
4.3 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due …

Feb 2, 2024
CVE-2024-1143
9.3 CRITICAL

Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

Feb 2, 2024
CVE-2024-1047
5.3 MEDIUM

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 2, 2024
CVE-2023-46045
7.8 HIGH

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically …

Feb 2, 2024
CVE-2024-24482
9.8 CRITICAL

Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

Feb 2, 2024
CVE-2024-21485
6.5 MEDIUM

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package …

Feb 2, 2024
CVE-2024-1073
6.4 MEDIUM

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due …

Feb 2, 2024
CVE-2024-0685
5.9 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via …

Feb 2, 2024
CVE-2023-38263
6.5 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-38020
4.3 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

Feb 2, 2024
CVE-2023-38019
8.1 HIGH

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Feb 2, 2024
CVE-2022-40744
4.8 MEDIUM

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 2, 2024
CVE-2024-22533
9.8 CRITICAL

Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the …

Feb 2, 2024
CVE-2024-22320
9.8 CRITICAL

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending …

Feb 2, 2024
CVE-2024-22319
8.1 HIGH

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an …

Feb 2, 2024
CVE-2023-46159
2.6 LOW

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force …

Feb 2, 2024
CVE-2024-23746
9.8 CRITICAL

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a …

Feb 2, 2024
CVE-2024-22903
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.