CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22902
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

Feb 2, 2024
CVE-2024-22901
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

Feb 2, 2024
CVE-2024-22900
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Feb 2, 2024
CVE-2024-22899
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Feb 2, 2024
CVE-2024-22779
8.8 HIGH

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

Feb 2, 2024
CVE-2023-50962
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

Feb 2, 2024
CVE-2023-50941
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using …

Feb 2, 2024
CVE-2023-50938
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Feb 2, 2024
CVE-2023-50935
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized …

Feb 2, 2024
CVE-2023-50934
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor …

Feb 2, 2024
CVE-2023-50328
3.7 LOW

IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

Feb 2, 2024
CVE-2023-48793
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

Feb 2, 2024
CVE-2023-48792
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

Feb 2, 2024
CVE-2023-46344
5.4 MEDIUM

A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting …

Feb 2, 2024
CVE-2023-32333
6.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

Feb 2, 2024
CVE-2024-21399
8.3 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 2, 2024
CVE-2023-50940
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information …

Feb 2, 2024
CVE-2023-50937
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50936
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. …

Feb 2, 2024
CVE-2023-50933
6.1 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

Feb 2, 2024
CVE-2023-50327
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50326
7.5 HIGH

IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force …

Feb 2, 2024
CVE-2024-22096
6.5 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific …

Feb 2, 2024
CVE-2024-22016
7.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege …

Feb 2, 2024
CVE-2024-21869
6.2 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker …

Feb 2, 2024
CVE-2024-21866
5.3 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it …

Feb 2, 2024
CVE-2024-21794
5.4 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

Feb 2, 2024
CVE-2024-21764
9.8 CRITICAL

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a …

Feb 2, 2024
CVE-2023-50939
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2024-24756
7.5 HIGH

Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. …

Feb 1, 2024
CVE-2024-23034
6.1 MEDIUM

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23033
6.1 MEDIUM

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23032
6.1 MEDIUM

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23031
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-22927
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-21852
8.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability …

Feb 1, 2024
CVE-2023-6221
7.7 HIGH

The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others …

Feb 1, 2024
CVE-2023-49617
10.0 CRITICAL

The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without …

Feb 1, 2024
CVE-2023-49610
8.1 HIGH

MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could …

Feb 1, 2024
CVE-2023-49115
7.5 HIGH

MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

Feb 1, 2024
CVE-2023-47867
8.8 HIGH

MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the …

Feb 1, 2024
CVE-2023-46706
9.1 CRITICAL

Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

Feb 1, 2024
CVE-2023-36496
7.7 HIGH

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

Feb 1, 2024
CVE-2024-24755
4.3 MEDIUM

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields …

Feb 1, 2024
CVE-2024-1040
4.4 MEDIUM

Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the …

Feb 1, 2024
CVE-2024-1039
9.8 CRITICAL

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management …

Feb 1, 2024
CVE-2024-0325
3.6 LOW

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.

Feb 1, 2024
CVE-2023-4472
9.8 CRITICAL

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated …

Feb 1, 2024
CVE-2023-47257
8.1 HIGH

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

Feb 1, 2024
CVE-2023-47256
5.5 MEDIUM

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

Feb 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.